Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Virus Spreading "w32.swem@mm"

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
Khephra Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 12:58 AM
Original message
Virus Spreading "w32.swem@mm"
Edited on Fri Sep-19-03 08:52 AM by Skinner
DO NOT UPDATE, OPEN OR INSTALL ANYTHING FROM WINDOWS RIGHT NOW OR FOR THE NEXT 24 HOURS AT LEAST THAT YOU DID NOT REQUEST.

Truthout is being attacked as is possibly other locations.

DO NOT OPEN OR INSTALL ANYTHING FROM MICROSOFT RIGHT NOW.

THE VIRUS WILL RE-WRITE YOUR REGISTRY
Printer Friendly | Permalink |  | Top
sasquatch Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 01:06 AM
Response to Original message
1. Thanks for warning us
Printer Friendly | Permalink |  | Top
 
AndyTiedye Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 01:26 AM
Response to Reply #1
3. Don't Open ANY attachment emailed from "Microsoft" EVER
Microsoft does not send patches as attachments.
All those emails everyone is getting claiming to be from Microsoft that contain attachments purporting to be patches are viruses themselves.


Printer Friendly | Permalink |  | Top
 
Hawkeye-X Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 01:13 AM
Response to Original message
2. Virus definitions updated as of 2 minutes ago
Check.
Printer Friendly | Permalink |  | Top
 
Selwynn Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 01:29 AM
Response to Reply #2
4. Roger
virus updates downloaded, and currently performing a scan, cause I'm paranoid :)
Printer Friendly | Permalink |  | Top
 
TahitiNut Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 01:30 AM
Response to Original message
5. I don't yet see a CERT or CIAC advisory
Edited on Fri Sep-19-03 01:37 AM by TahitiNut
... that might relate to your alarm. Could you provide some cite?

Is this what you're referring to? It's also here and characterized as a "Medium" threat to home users. It's an email-propagated virus, and is thus easily avoided by the ordinary precaution of never opening email attachments you're not absolutely certain about. I'm not confident it warrants unusual attention.
Printer Friendly | Permalink |  | Top
 
Khephra Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 01:38 AM
Response to Reply #5
6. dunno...just doing what I thought best
.
Printer Friendly | Permalink |  | Top
 
TreasonousBastard Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 01:54 AM
Response to Reply #5
8. You're right....
that it's easily avoided with a little common sense, but I got seven of them in an hour or so from people who apparently don't have that much sense and opened their "Microsoft" patches.

I have no problem with keeping the word out about these "patches" until everyone gets it.


Printer Friendly | Permalink |  | Top
 
starroute Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 10:19 AM
Response to Reply #5
23. This story says it also spreads via Kazaa and IRC
http://www.infoworld.com/article/03/09/18/HNinternetworm_1.html

The worm also can detect the presence of IRC clients or the Kazaa P-to-P file-sharing software and distribute itself on those networks. Swen places a specialized script file that sends a virus file to every computer on the same IRC channel as the infected computer.

For machines running Kazaa file-sharing software, Swen enables the file-sharing feature, if it is not already enabled, and places multiple copies of itself in the Kazaa shared files folder disguised as Kazaa client software, pirated software or other popular applications, F-Secure said.
Printer Friendly | Permalink |  | Top
 
TreasonousBastard Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 01:49 AM
Response to Original message
7. I just got home and found six emails with attachments...
and deleted the attachments.

Then I updated my AVG definitions, and then almost immediately got another spam with the same attachment, but AVG now caught the swem bug and isolated it. AVG just updated yesterday, and yet this is still a new one.

Damn, this is one hell of a fast game between the virus and anti-virus people. I've got a lot of respect for the AV people who are on top of this shit 24 hours a day.

Printer Friendly | Permalink |  | Top
 
lazarus Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 02:31 AM
Response to Reply #7
12. I normally get 2-3 a day
I got 95 today. 95. Filled up my mailbox, got legitimate mail bounced.

Luckily I use Agent, so I'm safe unless I get stupid and actually open something.
Printer Friendly | Permalink |  | Top
 
pretzel4gore Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 07:40 AM
Response to Reply #7
17. meanwhile the fbi is chasing pot growers!
they can trace these virus-spawners back to their hellholes...and SHOOT THEM imo....!
(but lotsa shooting down in langley then, i guess)
Printer Friendly | Permalink |  | Top
 
lfairban Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 01:55 AM
Response to Original message
9. I just got that e-mail.
It had links to Microsoft all over it, but the sender address wasn't. It seemed kind of funny to me.
Printer Friendly | Permalink |  | Top
 
Old and In the Way Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 01:59 AM
Response to Original message
10. My AV blocked the attachments, but the e-mail is really nasty
It looks like an official Microsoft e-mail that has their look and feel. It instructs you to load the attached .exe file. I'm sure this will be successful because it looks like an official Microsoft e-mail.

Microsoft does not send patches by e-mail....
Printer Friendly | Permalink |  | Top
 
twilight Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 02:09 AM
Response to Original message
11. just got home
:hi:

I just got home and turned on my computer and dialed in to my server. Norton Antivirus is on this one already as it began immediately downloading updates and I had just done this earlier today!

Thanks for the info. I never open attachments unless I know exactly what they are. Too risky!

:kick:
Printer Friendly | Permalink |  | Top
 
expatriot Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 04:15 AM
Response to Original message
13. wouldn't that be crazy if someone planted a virus in a Norton AV patch?
or a virus that somehow became a 'parasite' to the AV program that was sent to kill it and 'rode' the antivirus scanning program as it went through your entire computer, infectiing every single file in your computer. That'd suck.
Printer Friendly | Permalink |  | Top
 
EX-CONservative Donating Member (188 posts) Send PM | Profile | Ignore Fri Sep-19-03 05:31 AM
Response to Original message
14. The Virus...
I've gotten about 10 copies of this virus.

I know that Microsoft never sends patches via e-mail so I deleted it.

However, to a complete novice it looks authentic and many will be snookered in. This will likely cause some havoc.

If you actually get something from the microsoft.com website (NOT EMAIL!!!), it is safe.
Printer Friendly | Permalink |  | Top
 
spinbaby Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 07:12 AM
Response to Original message
15. This thing is prolific as hell
I've had dozens of them in my home email.
Printer Friendly | Permalink |  | Top
 
Kemet Donating Member (69 posts) Send PM | Profile | Ignore Fri Sep-19-03 07:28 AM
Response to Original message
16. Paypal scam
Edited on Fri Sep-19-03 07:30 AM by Kemet
I don't know if this fits in this thread but i thought i'd use this opportunity to warn people about this.
Yesterday i got an email that pretended to be from paypal asking me to verify my informations (i actually have a paypal account). The mail looked quite good with logo and everything. It provided a link wich looked like that: "http://www.paypal.com@212.254.32.32/verify".
While the scam was obvious at that point, i know that many people dont know that in an internet address that countains a @, everything before the @ doesnt count. If you ever get an email that countains a link that looks that way, don't even bother to click it, it's just trying to fool users into thinking it is legit.
Be safe

(edited: spelling)
Printer Friendly | Permalink |  | Top
 
soup Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 09:02 AM
Response to Reply #16
19. Everything before @ doesn't count?
Count me among the many people that didn't know.

thanks, Kemet :hi:
Printer Friendly | Permalink |  | Top
 
Eat_The_Rich Donating Member (106 posts) Send PM | Profile | Ignore Fri Sep-19-03 11:09 AM
Response to Reply #16
28. They are doing this with eBay also
very scary. Wern't these virus attacks supposed to stop once all these damn kids went back to school?
Printer Friendly | Permalink |  | Top
 
NNN0LHI Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 08:55 AM
Response to Original message
18. Put w32.swem@mm into Google. Here is what I got
Your search - w32.swem@mm - did not match any documents.
Printer Friendly | Permalink |  | Top
 
Tripper11 Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 09:20 AM
Response to Reply #18
20. Went to Symantec (Norton's AV) site and got this info
W32.Swen.A@mm

They have updates for it already and have listed it as a category 3 due to so many repsonses about it already.
Printer Friendly | Permalink |  | Top
 
PATRICK Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 09:54 AM
Response to Reply #20
21. not to be paranoid but
I get more spam purporting to be from from Norton than any other protection company. I notice too that the "caught" kids usually were playing around with an anonymous virus made by someone else.

Yet the trust system presupposed by the general populace who want to get along with the surface world is incredibly murky complex and seemingly regulated if at all in the digital shadows and ivory towers. We get used to endless wars and the strange inability to head off viruses in a timely fashion.

The price of downloading civilization into cyberspace.
Printer Friendly | Permalink |  | Top
 
Terran Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 09:56 AM
Response to Original message
22. Thanks Keph
I got something labeled Microsoft this AM, but it was at an address I don't think they would have any reason to have. Had a 154K attachment too, very suspicious, so it got trashed forthwith. Thanks for confirming this.

Dirk
Printer Friendly | Permalink |  | Top
 
LightTheMatch Donating Member (572 posts) Send PM | Profile | Ignore Fri Sep-19-03 10:21 AM
Response to Original message
24. Yawn... GET A MAC ALREADY!
n/t
Printer Friendly | Permalink |  | Top
 
MostlyBlackCat2 Donating Member (175 posts) Send PM | Profile | Ignore Fri Sep-19-03 10:34 AM
Response to Reply #24
26. wait a second
if everyone took that advice every time we told them to, eventually the virus writers would target us! It's kinda like not telling people how cool Canada is - that way it stays cool because all the fools don't migrate.
Printer Friendly | Permalink |  | Top
 
TrogL Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 02:56 PM
Response to Reply #26
37. It's the operating system
Windoze is inherently insecure.

For the amount of time spent today fucking around with viruses and patches in my office, we could afford to completely retool with Macs.

I've gotten almost nothing accomplished in terms of real work.
Printer Friendly | Permalink |  | Top
 
Forkboy Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 12:52 PM
Response to Reply #24
32. I will as soon as I can play my games on them
:)
Printer Friendly | Permalink |  | Top
 
EV1Ltimm Donating Member (831 posts) Send PM | Profile | Ignore Fri Sep-19-03 12:58 PM
Response to Reply #24
33. let me go buy a helmet first...
i mean, i might as well look the part, right?

:)
Printer Friendly | Permalink |  | Top
 
spinbaby Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 12:59 PM
Response to Reply #24
34. It infects Macs
Check the Symantec site and don't be so smug about using a Mac.

Printer Friendly | Permalink |  | Top
 
Terran Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 02:48 PM
Response to Reply #24
36. Yeah, right
I'll live with the viruses, thanks. :eyes:
Printer Friendly | Permalink |  | Top
 
FlaGranny Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 10:25 AM
Response to Original message
25. People should really get on their e-mail servers
about these viruses. They could be filtered out before they ever get to you. My ISP does it, so there's no reason others can't. I use bellsouth. I believe they tightened up their filters several months ago and I haven't had an e-mail virus since. I don't get spam either.
Printer Friendly | Permalink |  | Top
 
Don_G Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 10:47 AM
Response to Original message
27. Nortons AV Added This To Their Updates Today
I downloaded it this morning.
Printer Friendly | Permalink |  | Top
 
Fovea Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 11:19 AM
Response to Original message
29. Norton caught it and deleted it on my machine
Windows... blech.
Printer Friendly | Permalink |  | Top
 
Speck Tater Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 11:47 AM
Response to Original message
30. Having a Mac won't help

I still got 88 copies of this infested email yesterday and when I checked my email this morning I had 147 more copies in my inbox overnight. Granted, the worm won't infect a Mac, but it still bogs down incoming email on a dial up line regardless of what system you use.
Printer Friendly | Permalink |  | Top
 
spinbaby Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 01:01 PM
Response to Reply #30
35. Doesn't matter
It infects Outlook or Outlook Express on whatever system you're using--even Macs. Microsoft products are like virus magnets.
Printer Friendly | Permalink |  | Top
 
TrogL Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Sep-19-03 12:39 PM
Response to Original message
31. Do we know exactly what is doing this?
I've gotten two in the last two minutes and they don't fit the description of the links below.

Mine are from


  • Net Message Delivery service subject Bug Message
  • Microsoft Security Assistance
  • net delivery system Subject Bug Message
  • Microsoft Technical Bulletin subject Newest Net Critical Update


Received: from a34-mta01.direcway.com (actually a34-mta01.direcpc.com)
Date-warning: Date header was inserted by a34-mta01.direcway.com
From: Microsoft Security Assistance <mogtbgql@newsletters.com>
To: <customer.txiuoejdgo@newsletters.com>
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Mon Apr 29th 2024, 12:54 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC