Notices
Non Scooby Related Anything Non-Scooby related

Beware of patches claiming to be from microsoft

Thread Tools
 
Search this Thread
 
Old Sep 19, 2003 | 05:09 PM
  #1  
windyboy's Avatar
windyboy
Thread Starter
Scooby Regular
 
Joined: Jan 2003
Posts: 1,591
Likes: 0
From: Working in Belfast and living in Bangor, N'orn I'ron
Exclamation

http://www.theregister.co.uk/content/56/32925.html


Nasty worm poses as MS security update
By John Leyden
Posted: 19/09/2003 at 08:03 GMT

Windows users were yesterday warned of the appearance of a worm that poses as a security update from Microsoft but actually causes all manner of mischief on infected PCs.

Swen-A (AKA Gibe-F) is a mass-mailing worm that also attempts to spread through file-sharing networks, such as KaZaA and IRC, and over local area network shares. The worm attempts to de-activate antivirus and personal firewall programs running on an infected computer.

AV vendors warn that the worm is spreading rapidly and that disinfection is difficult. As usual this is a Windows-only menace Linux, Macintosh, Microsoft OS/2 and Unix users are immune.

Swen-A uses a well known vulnerability in Internet Explorer to execute directly from e-mail. Windows users can also catch the pox by executing an infected email attachment.

Finnish AV firm F-Secure compares the worm to Gibe, and believes it is likely that the same author wrote both worms.

Swen-A (like Gibe and numerous other viruses before it) purports to be a security alert from Microsoft. This time around infectious messages come with a well-presented HTML message complete with graphics that are more likely to trip up the unwary.

The worm can also impersonate mail delivery failure notices, attaching itself as a randomly named executable.

Swen-A attempts to spread by emailing itself using its own SMTP client to addresses extracted from various sources on the victim's drives (e.g.MBX and DBX files). Periodically the worm presents users with a fake MAPI Exception error, prompting them to enter the details of their email account (name, user name, servers).

Sneaky.

Swen-A also makes modifications which make it hard to run Reg Edit,
along with other changes to infected PCs explained in advisories from F-Secure and Symantec.

Windows users are advised to update the virus signature files on their AV scanners to defend themselves against the worm, which is all very well but the reason the virus got a hold in the first place is probably because of the shortcomings of the scanner model.

You have been warned...
Windyboy
Reply
Old Sep 19, 2003 | 05:22 PM
  #2  
alcazar's Avatar
alcazar
Scooby Regular
20 Year Member
Liked
Loved
Community Favorite
iTrader: (2)
 
Joined: Jun 2002
Posts: 40,788
Likes: 30
From: Rl'yeh
Angry

Ooooooooooh! I'd love half an hour in a locked room with the sort of people who write these things.WTF do they get out of it? sad fekkers!!
I've only just got rid of that last b@st@rd worm, Welchia, was it??
Alcazar:
Reply
Old Sep 19, 2003 | 05:26 PM
  #3  
shunty's Avatar
shunty
Scooby Regular
 
Joined: Aug 2001
Posts: 2,082
Likes: 0
From: wakefield
Talking

keeps us all in a job though mate

shunty
Reply
Old Sep 19, 2003 | 05:27 PM
  #4  
Hobo_Jojo's Avatar
Hobo_Jojo
Scooby Regular
 
Joined: Aug 2003
Posts: 1,981
Likes: 0
Post

when will people stop opening unknown atachments in emails from unrecognised adresses??
Reply
Old Sep 19, 2003 | 06:57 PM
  #5  
andrewdelvard's Avatar
andrewdelvard
Scooby Regular
 
Joined: Sep 2001
Posts: 3,079
Likes: 0
From: Plymouth
Thumbs up

Thanks for the warning.
Reply
Old Sep 19, 2003 | 07:14 PM
  #6  
Boro's Avatar
Boro
Scooby Regular
iTrader: (1)
 
Joined: Jul 2003
Posts: 7,222
Likes: 0
From: Cornwall
Post

I NEVER open email from addresses i dont know.

BUT..... the other day i got one subject; Undelivered Message (or something similar)... Sender: MAILER-DAEMON.

I couldnt remember the exact senders details for a genuine returned email and clicked it

It was some advertising crap. But it DID catch me out.
Reply
Old Sep 19, 2003 | 07:39 PM
  #7  
WRX Wannabe's Avatar
WRX Wannabe
Scooby Regular
 
Joined: Apr 2003
Posts: 1,211
Likes: 0
From: Watford
Post

$hit i had that sent to me today
Reply
Old Sep 19, 2003 | 07:48 PM
  #8  
WRX Wannabe's Avatar
WRX Wannabe
Scooby Regular
 
Joined: Apr 2003
Posts: 1,211
Likes: 0
From: Watford
Post

1st came up as an undelivered mail?

Then a link to MS?

I did not open as i thought it was strange

Have done a virus sweep and all is fine

Reply
Old Sep 19, 2003 | 10:16 PM
  #9  
Maddriver's Avatar
Maddriver
Scooby Regular
 
Joined: Aug 2002
Posts: 101
Likes: 0
Post

Yep had this at work

Norton AV caught the virus in the attachment.
Reply
Old Sep 20, 2003 | 12:13 PM
  #10  
Leslie's Avatar
Leslie
Scooby Regular
 
Joined: Aug 2002
Posts: 39,877
Likes: 0
Post

Thanks for the tip

Les
Reply
Old Sep 20, 2003 | 12:28 PM
  #11  
nkh's Avatar
nkh
Scooby Regular
 
Joined: May 2002
Posts: 633
Likes: 0
Post

Yep I got that this morning
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Mattybr5@MB Developments
Full Cars Breaking For Spares
38
Jul 17, 2016 10:43 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
Dec 28, 2015 11:07 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
Nov 18, 2015 07:03 AM
InTurbo
ScoobyNet General
21
Sep 30, 2015 08:59 PM
alcazar
Non Scooby Related
13
Sep 15, 2015 02:39 PM




All times are GMT +1. The time now is 01:17 PM.