Where does swen take you?

F

Fludge

Hi.
I posted on here a while back about my parent's, and how they had swen. The
norton thingy removed it, and I know people were pretty mad that they were
stupid enough to have got it and thereby propogated this crap.

Well, don't laugh or scream, but I think they've contrived to get it again.
I just need some advice on what happens with SWEN if you assimilate it more
than once, because this isn't like the last time.

I rang them up to tell them about the 'not' mail rule, and they booted up
whilst on the phone. Or at least, they tried to. Before the desktop, but
after the Windows logo, the old memory kernel message thingy appeared. Last
time they had swen, this didn't show up until after the desktop had loaded.

Then, on a black screen, they got a windows updating files box, or something
similarly named, with a progression bar that froze half way through.

On rebooting, the kernel message appeared as before, but then, apparently, a
box in the bottom left, simply said 'error occured'. Then everything froze.

Is this swen again? If so, is it terminal, will they need to reformat, or
is there something to be done? I know I know, how could they be so stupid.
And I'm sorry to hit the newsgroup with yet another swen enquiry, but I
really could do with some advice to pass onto them later. Can anyone help?
Thanks again.
 
G

Guest

| Hi.
| I posted on here a while back about my parent's, and how they had swen.
The
| norton thingy removed it, and I know people were pretty mad that they were
| stupid enough to have got it and thereby propogated this crap.
|
| Well, don't laugh or scream, but I think they've contrived to get it
again.
| I just need some advice on what happens with SWEN if you assimilate it
more
| than once, because this isn't like the last time.
|
| I rang them up to tell them about the 'not' mail rule, and they booted up
| whilst on the phone. Or at least, they tried to. Before the desktop, but
| after the Windows logo, the old memory kernel message thingy appeared.
Last
| time they had swen, this didn't show up until after the desktop had
loaded.
|
| Then, on a black screen, they got a windows updating files box, or
something
| similarly named, with a progression bar that froze half way through.
|
| On rebooting, the kernel message appeared as before, but then, apparently,
a
| box in the bottom left, simply said 'error occured'. Then everything
froze.
|
| Is this swen again? If so, is it terminal, will they need to reformat, or
| is there something to be done? I know I know, how could they be so
stupid.
| And I'm sorry to hit the newsgroup with yet another swen enquiry, but I
| really could do with some advice to pass onto them later. Can anyone
help?
| Thanks again.
|

OK, I'm serious, I don't often say this, but if they are not smart enough to
learn from one mistake, install anti-virus software, and keep it up to day,
and stop clicking on attachments that they don't expect, they are _not_ fit
to be using a full-featured computer connected tot he public internet.

Have them pack up their computer and return it to the store, and buy one of
these "mailstations" (if they feel they cannot live without email).
Alternatively, buy them a fax.

SB
 
F

Fludge

What's the point of being so intollerant on a group that, as a community,
should be trying to help people get over problems. If we can't educate
people then they're only going to go on making the same mistakes, and we
have to put up with the SPAM. That advice is about as constructive as
coalition forces shooting dead children in Iraq, thanks.
 
B

Bart Bailey

In Message-ID:<[email protected]> posted on Mon, 6
What's the point of being so intollerant on a group that, as a community,
should be trying to help people get over problems.

What's the point of top posting?
Trying to alienate those who would help you?
 
N

nicky

Fludge said:
What's top posting?

It's what you do: typing your response above instead of below the post you
are replying to. It makes the post hard to understand as we don't know what
your replying to unless we scroll down. Top posting also ruins the flow of a
discussion or Qs and As

nicky
 
F

Frans Meijer

OK, I'm serious, I don't often say this, but if they are not smart enough to
learn from one mistake, install anti-virus software, and keep it up to day,

Pointless, the patterns that should have detected swen were released too
late anyway.
and stop clicking on attachments that they don't expect,

Very important point. And get them a less vulnerable email client and
webbrowser.
 
G

Guest

| What's the point of being so intollerant on a group that, as a community,
| should be trying to help people get over problems. If we can't educate
| people then they're only going to go on making the same mistakes, and we
| have to put up with the SPAM. That advice is about as constructive as
| coalition forces shooting dead children in Iraq, thanks.
|

The point is that your parents are trying to learn how to drive, while
speeding with 350 miles per hour over over 4-lane highway!
I don't give a hoot about how much damage they do to themselvs while
learning, but they (and people like them) to a boatload of damage to the
internet as a whole.

I have been receiving over 100 Swen emails per hour in the first week. It
has now quieted down a bit to "only" 20 per hour... This is at one single
email address!


SB
 
F

Fludge

Spam Buster said:
| What's the point of being so intollerant on a group that, as a community,
| should be trying to help people get over problems. If we can't educate
| people then they're only going to go on making the same mistakes, and we
| have to put up with the SPAM. That advice is about as constructive as
| coalition forces shooting dead children in Iraq, thanks.
|

The point is that your parents are trying to learn how to drive, while
speeding with 350 miles per hour over over 4-lane highway!
I don't give a hoot about how much damage they do to themselvs while
learning, but they (and people like them) to a boatload of damage to the
internet as a whole.

I have been receiving over 100 Swen emails per hour in the first week. It
has now quieted down a bit to "only" 20 per hour... This is at one single
email address!


SB

Alright, fair enough. In the defence of those who have been careless or
naive enough to contract this particular virus, Various recent virus' have
been all over the national press here in the UK, people making a lot of fuss
about this that and the other potentially crippling virus, but I myself
hadn't heard about swen until after it had began its dirty deeds. There are
heads up for some virus', but others catch you on the blindside. Maybe I
just missed the warnings about this one, but it didn't seem that well
publisized.
 
R

R

I too have been receiving 100 swen emails per hour. How so many people have
my email address I do not know. I have been replying to them with an email
saying that they need to check their PCs vor viruses. You have to look up
the mime header for the true return address though. I have also posted
information on some newsgroups.


THIS IS NOT A SPAM EMAIL/NEWSGROUP POST. You may be unaware but there is a
new malicious virus going around that causes you to send out emails with
viruses. These emails will already have been sent to everyone on your
contact list/address book if you have it. Please urgently forward this
email to everyone on your contacts/address book so that they may check their
own PC. Do not worry about sending them the virus, you will have already
done so if you do have the virus! This is microsoft's report on this virus.
http://www.microsoft.com/security/antivirus/authenticate_mail.asp

The fact that you are sending out these virus infected emails indicates that
you probably have a virus on your PC that is automatically sending out
emails with viruses without your knowledge. You can verify below whether or
not you may have the virus. After reading this you should virus check your
PC with the latest anti virus definitions. If you do not have anti virus
software you should connect to the internet and click here Scan your PC for
viruses now!
http://click.linksynergy.com/fs-bin/click?id=jGkJDpd6dW0&offerid=50252.6&type=1&subid=0

Only email me if you wish more info and want to opt in to a mailing list.
----------------------------------------------------------------------------
----

Extract from Anti Virus companies regarding "W32.Swen.A@mm" worm.
NOTE: This threat was previously detected as Worm.Automat.AHB

Due to an increase in submissions, this has been upgraded W32.Swen.A@mm to
Category 3, as of 6:30pm Thursday, September 18, 2003. It is also rapidly
heading towards being a high risk.

W32.Swen.A@mm is a mass-mailing worm that uses its own SMTP engine to spread
itself.

The worm can arrive as an email attachment. The subject, body, and from
address of the email may vary. Some examples claim to be patches for
Microsoft Internet Explorer, or delivery failure notices from qmail.

This worm exploits a vulnerability in Microsoft Outlook and Outlook Express
in an attempt to execute itself when you open or even preview the email. If
you do not have anti virus software you should connect to the internet and
click here Scan your PC for viruses now!


Information and a patch for the vulnerability IF YOU DO NOT ALREADY HAVE THE
VIRUS can be found at
http://www.microsoft.com/technet/security/bulletin/MS01-020.asp
however this will only protect you IF YOU DO NOT ALREADY HAVE THE VIRUS.
Install this patch after you confirm that you are clear of the virus.

Here is some information on what the virus does:

1. This virus attempts to trick you into installing it by pretending to be
a security vulnerability patch from Microsoft.

2. Upon executing it asks if you want to install the latest security
patch.

3. If you say no, it still installs itself but without your knowledge. If
you say yes then it displays messages that appear that it is installing an
update to windows.

4. Modifies the value:

"DisableRegistryTools" = "1"

in the registry key:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System

TO PREVENT THE USER RUNNING REGEDIT ON THE COMPUTER (see below*)

5. Puts a copy of itself to %Windir% with a randomly generated filename.


6. Searches .html, .asp, .eml, .dbx, .wab, .mbx files on the computer for
email addresses.


7. Creates the file, %Windir%\Germs0.dbv, where it stores the email
addresses it has found.


8. Creates the file, %Windir%\Swen1.dat, where it stores a list of remote
news and mail servers.


9. Adds the following values to the registry:

"Server"="<The IP address of the SMTP server that the worm retrieves from
the registry>"
"Mirc Install Folder"="<location of mirc client on system>"
"Installed"="...by Begbie"
"Install Item"="<random>"
"Unfile"="<random>"
"CacheBox Outfit"="yes"
"ZipName"="<random>"
"Email Address"="<The current users email address that the worm retrieves
from the registry>"
to the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\<rando
m set of letters>


10. So that it can run itself it adds a randomly named value to:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

11. Modifies the registry keys:
HKEY_LOCAL_MACHINE\Software\CLASSES\regfile\shell\open\command
HKEY_LOCAL_MACHINE\Software\CLASSES\scrfile\shell\open\command
HKEY_LOCAL_MACHINE\Software\CLASSES\comfile\shell\open\command
HKEY_LOCAL_MACHINE\Software\CLASSES\batfile\shell\open\command
HKEY_LOCAL_MACHINE\Software\CLASSES\piffile\shell\open\command
HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell\open\command

12. Checks the computer to find messages sent by itself and deletes them
so there is no trace that the PC has sent any virus infected emails.

How do you know if you've been infected?

Display of a series of dialog boxes
Unexpected termination of various security and anti-virus products.
Inability to run RegEdit on the victim's machine


*IF YOU CANNOT RUN REGEDIT ON YOUR PC YOU ARE PROBABLY INFECTED or this has
been turned off by your computer system administrator. If you are on a
network check with your system administrator.

Click <start>, Click <run>, type regedit and click <OK>. Registry editor
should run, it looks similar to windows explorer but has a name of Registry
Editor in the name bar at the top. If it has run ok then close it with the
X in top right. If the program ran ok this does not confirm that you are
not infected. It could mean that your registry may be corrupted and the
virus was unable to stop the program from running.

For further information visit Anti Virus now!
http://click.linksynergy.com/fs-bin/click?id=jGkJDpd6dW0&offerid=50252.6&type=1&subid=0
 
G

Gabriele Neukam

On that special day, R, ([email protected]) said...
I too have been receiving 100 swen emails per hour. How so many people have
my email address I do not know. I have been replying to them with an email
saying that they need to check their PCs vor viruses. You have to look up
the mime header for the true return address though. I have also posted
information on some newsgroups.

(snip gigantic text portion)

R,

would you please be so kind and NOT post this text into unrelated
newsgroups like de.admin.net-abuse.mail
(see Message-ID: <[email protected]>)?

We are very well aware of the problem, have discussed it at length, and
know how to deal with it.

And the infected "poster" does probably not even read the group danam,
as the worm retrieves addresses and sends its messages at random,
identifying newsgroups not by name, but by some indexing number. It
might well be that the "poster" normally does only read
alt.fan.elvis.seen.on.mars, and nothing else, while Swen decided to post
into group number Idunnowhat.

So please make your automaton behave more properly, will you?


Gabriele Neukam

(e-mail address removed)
 
J

John and Pat Ochenduszko

Frans Meijer said:
day,

Pointless, the patterns that should have detected swen were released too
late anyway.


Very important point. And get them a less vulnerable email client and
webbrowser.

And possibly enable a mail rule that will delete from the server any message
with an attachment. If they are not sure which mail is safe and which is
not, then I would error on the side of extreme caution and delete off the
server any and all mail that contains attachment. When the Swen dies off
then allow attachment laden mail to be downloaded. Might be a bit extreme
but far less aggravation for them and you (meaning Fludge). And I can
sympathize since I have gone through similar instances with friends.

Regards,
John O.
 
G

Guest

[snip]
| Alright, fair enough. In the defence of those who have been careless or
| naive enough to contract this particular virus, Various recent virus' have
| been all over the national press here in the UK, people making a lot of
fuss
| about this that and the other potentially crippling virus, but I myself
| hadn't heard about swen until after it had began its dirty deeds. There
are
| heads up for some virus', but others catch you on the blindside. Maybe I
| just missed the warnings about this one, but it didn't seem that well
| publisized.
|

True, but still: the only good protection against viruses is: up-to-date
virus checker and not clicking attachments. How is not having a warning
gonna make a difference?


SB
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top