Notices
Non Scooby Related Anything Non-Scooby related

Beware of patches claiming to be from microsoft

Thread Tools
 
Search this Thread
 
Old 19 September 2003, 05:09 PM
  #1  
windyboy
Scooby Regular
Thread Starter
 
windyboy's Avatar
 
Join Date: Jan 2003
Location: Working in Belfast and living in Bangor, N'orn I'ron
Posts: 1,591
Likes: 0
Received 0 Likes on 0 Posts
Exclamation

http://www.theregister.co.uk/content/56/32925.html


Nasty worm poses as MS security update
By John Leyden
Posted: 19/09/2003 at 08:03 GMT

Windows users were yesterday warned of the appearance of a worm that poses as a security update from Microsoft but actually causes all manner of mischief on infected PCs.

Swen-A (AKA Gibe-F) is a mass-mailing worm that also attempts to spread through file-sharing networks, such as KaZaA and IRC, and over local area network shares. The worm attempts to de-activate antivirus and personal firewall programs running on an infected computer.

AV vendors warn that the worm is spreading rapidly and that disinfection is difficult. As usual this is a Windows-only menace Linux, Macintosh, Microsoft OS/2 and Unix users are immune.

Swen-A uses a well known vulnerability in Internet Explorer to execute directly from e-mail. Windows users can also catch the pox by executing an infected email attachment.

Finnish AV firm F-Secure compares the worm to Gibe, and believes it is likely that the same author wrote both worms.

Swen-A (like Gibe and numerous other viruses before it) purports to be a security alert from Microsoft. This time around infectious messages come with a well-presented HTML message complete with graphics that are more likely to trip up the unwary.

The worm can also impersonate mail delivery failure notices, attaching itself as a randomly named executable.

Swen-A attempts to spread by emailing itself using its own SMTP client to addresses extracted from various sources on the victim's drives (e.g.MBX and DBX files). Periodically the worm presents users with a fake MAPI Exception error, prompting them to enter the details of their email account (name, user name, servers).

Sneaky.

Swen-A also makes modifications which make it hard to run Reg Edit,
along with other changes to infected PCs explained in advisories from F-Secure and Symantec.

Windows users are advised to update the virus signature files on their AV scanners to defend themselves against the worm, which is all very well but the reason the virus got a hold in the first place is probably because of the shortcomings of the scanner model.

You have been warned...
Windyboy
Old 19 September 2003, 05:22 PM
  #2  
alcazar
Scooby Regular
iTrader: (2)
 
alcazar's Avatar
 
Join Date: Jun 2002
Location: Rl'yeh
Posts: 40,781
Received 27 Likes on 25 Posts
Angry

Ooooooooooh! I'd love half an hour in a locked room with the sort of people who write these things.WTF do they get out of it? sad fekkers!!
I've only just got rid of that last b@st@rd worm, Welchia, was it??
Alcazar:
Old 19 September 2003, 05:26 PM
  #3  
shunty
Scooby Regular
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Talking

keeps us all in a job though mate

shunty
Old 19 September 2003, 05:27 PM
  #4  
Hobo_Jojo
Scooby Regular
 
Hobo_Jojo's Avatar
 
Join Date: Aug 2003
Posts: 1,981
Likes: 0
Received 0 Likes on 0 Posts
Post

when will people stop opening unknown atachments in emails from unrecognised adresses??
Old 19 September 2003, 06:57 PM
  #5  
andrewdelvard
Scooby Regular
 
andrewdelvard's Avatar
 
Join Date: Sep 2001
Location: Plymouth
Posts: 3,079
Likes: 0
Received 0 Likes on 0 Posts
Thumbs up

Thanks for the warning.
Old 19 September 2003, 07:14 PM
  #6  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Post

I NEVER open email from addresses i dont know.

BUT..... the other day i got one subject; Undelivered Message (or something similar)... Sender: MAILER-DAEMON.

I couldnt remember the exact senders details for a genuine returned email and clicked it

It was some advertising crap. But it DID catch me out.
Old 19 September 2003, 07:39 PM
  #7  
WRX Wannabe
Scooby Regular
 
WRX Wannabe's Avatar
 
Join Date: Apr 2003
Location: Watford
Posts: 1,211
Likes: 0
Received 0 Likes on 0 Posts
Post

$hit i had that sent to me today

Trending Topics

Old 19 September 2003, 07:48 PM
  #8  
WRX Wannabe
Scooby Regular
 
WRX Wannabe's Avatar
 
Join Date: Apr 2003
Location: Watford
Posts: 1,211
Likes: 0
Received 0 Likes on 0 Posts
Post

1st came up as an undelivered mail?

Then a link to MS?

I did not open as i thought it was strange

Have done a virus sweep and all is fine

Old 19 September 2003, 10:16 PM
  #9  
Maddriver
Scooby Regular
 
Maddriver's Avatar
 
Join Date: Aug 2002
Posts: 101
Likes: 0
Received 0 Likes on 0 Posts
Post

Yep had this at work

Norton AV caught the virus in the attachment.
Old 20 September 2003, 12:13 PM
  #10  
Leslie
Scooby Regular
 
Leslie's Avatar
 
Join Date: Aug 2002
Posts: 39,877
Likes: 0
Received 0 Likes on 0 Posts
Post

Thanks for the tip

Les
Old 20 September 2003, 12:28 PM
  #11  
nkh
Scooby Regular
 
nkh's Avatar
 
Join Date: May 2002
Posts: 633
Likes: 0
Received 0 Likes on 0 Posts
Post

Yep I got that this morning
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mattybr5@MB Developments
Full Cars Breaking For Spares
38
17 July 2016 10:43 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
28 December 2015 11:07 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
18 November 2015 07:03 AM
InTurbo
ScoobyNet General
21
30 September 2015 08:59 PM
alcazar
Non Scooby Related
13
15 September 2015 02:39 PM



Quick Reply: Beware of patches claiming to be from microsoft



All times are GMT +1. The time now is 11:52 PM.