'Swen' worm poses as security patch

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

Topics

swen, Viruses, Worm

NEWS
Antivirus companies are warning of a new Windows worm that has the potential to spread quickly because it appears to be a legitimate security update from Microsoft.

For information on how to combat the worm, click here.

The Swen worm, known technically as I-Worm.Swen, W32/Swen.A@mm or W32/Gibe@MM.e, affects Windows 95, Windows NT and all newer versions, and spreads via email and through IRC, Kazaa and local area networks. It uses a vulnerability in Internet Explorer to execute directly from an email message, according to F-Secure. It also attempts to disable firewall and antivirus software. The worm first appeared in the wild on Thursday.

Windows users are still reeling from a series of damaging virus attacks that have caused chaos in recent weeks, partly due to the large number of Internet-connected PCs that have not patched known vulnerabilities.

One of the emails Swen uses to spread is a professional-looking message that appears to come from "MS Technical Assistance", and contains a notification of a "September 2003, Cumulative Patch", along with the virus attachment. Microsoft does not spread updates via email.

When executed, the worm continues to pose as a security update, launching a message windows that states: "This will install Microsoft Security Update. Do you wish to continue?" If the user clicks "Yes" the worm shows a fake installation dialogue box, but also installs invisibly if the "No" button is pressed.

Swen installs various files to ensure that it is launched every time the system boots up. It also disables the user's ability to edit the Registry.

Users are advised not to launch attachments. Symantec, F-Secure, Sophos, Network Associates and others have updated the definitions in their anti-virus software to prevent Swen infections.

Talkback

What never ceases to amaze me...is that all of these virus's/bugs/worms...they make the news! Yet have I found the reporting source tell you where you can find a fix. I wouldnt have logged onto your site just to read about the Swen worm...just to find out about it characteristics? Where can you find a patch/removal...even if you have to pay for it?

via Facebook 19 September, 2003 01:37
Reply

Great job. I knew it had to be a hoax at least a worm at the worst. I knew M$ wouldn't send out patches, but with a Google search at 8:40pm EST only ZDNET turned up with the answer. Great job on being on the cutting edge since my Anti-virus software was up to date and it didn't stop it.

via Facebook 19 September, 2003 01:54
Reply

People People! Its very important to keep up to date with any possible virus attack. Please remember they are all preventable if you would just keep your virus definitions UP TO DATE. Which means clicking on the update buttons at least once a week. Simple! And please install those Firewalls! Tsk Tsk :)

via Facebook 19 September, 2003 16:08
Reply

Here we go again, this spoof email is going to FOOL a lot of people....
I just received this spoof email that appears to be a legitimate security update from Microsoft. I have so get so many spoof emails that looks like a PayPal or eBay email that I'm very careful about any email asking for passwords, credit card #, ss#, update personl information, my name of my 1st born child. :-) If I'm not sure if it's a spoof email I go to the website .....(DO NOT CLICK ON ANY LINK IN THE EMAIL)
That's my 2 cents worth.

via Facebook 19 September, 2003 16:59
Reply

Better than manual update is automatic update. I have NAV 2003 and it automatically updates definitions all the time. I got this virus several times in my mail account as a MS update. The people that spend their time creating this crap should get atleast 20 years in prison w/ no early parole, for this crime, when convicted. I hope that kid the Feds arrested, once proven guilty, gets the maximum sentence! I've only been hit by one virus but it did enough damage, including loss of valuable data, that I would gladly rap my fingers around the perp's throat and squeeze!

via Facebook 19 September, 2003 18:07
Reply

You can get a free fix for swen virus from

http://www3.ca.com/virusinfo/virus.aspx?ID=36939

via Facebook 21 September, 2003 15:09
Reply

How do you know if you have the worm in your system i run xp home i have A V G 6 anti virus spy bot
but i think i have had the worm put into my system i opened up an email before i new of the worm i do all the things they tell me to do with all my anti virus and it tells me that every thing is clear on my system can i beleive it ?? or is it still there??

via Facebook 22 September, 2003 07:10
Reply

re: keeping up to date on definitions.
NAV set for auto update. Every day it flashes a dialog box declaring my definitions not up to date. But when it goes to NAV website, invariably it immediately responds that the only Symantec product I have is Update and that there are no current updates that I need.
And, it indicates my last update to be weeks ago. The "old" date it is showing is my last manual update. When I recently downloaded the manual definitions package and initiated a full system scan, it came up with 2 unrepairable viruses. These conflicting messages leave me very uneasy about my NAV subscription.

via Facebook 1 October, 2003 05:54
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

44 seconds ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

2 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

3 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

3 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

4 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

5 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

6 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

12 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

14 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

14 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

16 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

16 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

17 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

18 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

18 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

18 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

19 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

19 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

19 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

19 hours ago by Moley on ACTA: Facts, misconceptions and questions