also @ TechSpot: HP TouchPad running Android 4.0 Ice Cream Sandwich
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > TechSpot Community > General Discussion

Begin your free trial now Pay-as-you-go options starting at $10/user/month

New Virus Worm replicates via email, network IRC and Kazaa

Thread Tools Search this Thread
  #1  
Old 09-20-2003
Per Hansson's Avatar
TechSpot Server Guru
 
Location: Sweden
Member since: Feb 2002, 1,513 posts
System specs
New Virus Worm replicates via email, network IRC and Kazaa

Just a few minutes ago I received a mail that looked very legitimate, it came from "Security Division" with the subject "Latest Internet Patch" when I opened it up I was greeted by the look and feel of emails Microsoft sends out:

this is the latest version of security update, the "September 2003, Cumulative Patch" update which fixes all known security vulnerabilities affecting MS Internet Explorer, MS Outlook and MS Outlook Express. Install now to protect your computer. This update includes the functionality of all previously released patches.

Of course I scanned the attachment and sure enough it was a virus, it's name was "Swen" F-Secure has rated this virus at Level 1: The highest warning a virus can get. Click this link to see an image (127kb) of the email I received. Also see MS01-020 for a fix to the vulnerability this virus makes use of. F-Secure (linked above) has free removal tools for this virus available for download.
Swen is a mass-mailer, which was first found on Thursday, September 18th, 2003. This rather complex worm uses several different techniques to spread and can, unlike most other e-mail worms, execute automatically when an infected e-mail message is received. Swen can also, in addition to e-mail, use IRQ chat, Kazaa networks and shared folders in local area networks to spread. Original article
__________________
"The one who says it cannot be done should never interrupt the one who is doing it."
  #2  
Old 09-20-2003
StormBringer's Avatar
TechSpot Evangelist
 
Location: USA
Member since: Apr 2002, 2,871 posts
Heh, C-Net only has it listed as a level6
http://reviews.cnet.com/4520-6600_7-...g=cnetfd.virus

Symantec has some very detailed info on it with pictures. http://www.symantec.com/avcenter/ven...swen.a@mm.html
  #3  
Old 09-21-2003
TS | Thomas's Avatar
TechSpot Maniac
 
Location: Ireland
Member since: Feb 2002, 1,327 posts
Yeah, my wife got one of those mails yesterday. Looks fine enough until you check the message headers & all
  #4  
Old 09-21-2003
Phantasm66's Avatar
TechSpot Evangelist
 
Location: Glasgow, Scotland
Member since: Feb 2002, 6,504 posts
Thanks very much for this. I have e-mailed all of the mortals in my department to tell them about it in terms that mortals will understand...
  #5  
Old 09-21-2003
TS | Thomas's Avatar
TechSpot Maniac
 
Location: Ireland
Member since: Feb 2002, 1,327 posts
Email that says it's from Microsoft = Bad.
  #6  
Old 09-21-2003
Mictlantecuhtli's Avatar
TechSpot Special Forces
 
Location: Finland
Member since: Feb 2002, 4,886 posts
System specs
Quote:
Originally posted by TS | Thomas
Looks fine enough until you check the message headers & all
"this is the latest version of security update ... which fixes all known security vulnerabilities affecting MS Internet Explorer, MS Outlook and MS Outlook Express."

Mail size in Per's screenshot: 157 kB.

I guess they've done pretty good a job then
  #7  
Old 09-21-2003
filkertom's Avatar
Newcomer, in training
 
Member since: Sep 2003, 5 posts
See, this is why I don't want MS to have automatic updates that you have no control over. Computers can be hacked. The mail certainly looks legit, if you just give it a glance -- but the knowledge that MS announces patches, and tells people through press releases to run the Windows Update, rather than e-mailing them, is often forgotten by non-techies, and, I'd bet, even by a few techies. Just think of what damage could be done if some unscrupulous lamer could send out an "official MS update" that you couldn't cancel.
Closed Thread

Similar Topics
Topic Replies Forum
Virus or Worm? 1 Virus and Malware Removal
Have a virus or worm I cant get out. 3 Windows OS
Yada Email Worm Mutatis 2 General Discussion
Kazaa to fold.... But will this stop the network??? 6 General Discussion
Stealth P2P Network inside KaZaa to be activated soon 0 General Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 01:47 PM.