20/09/2003

Swen.A


New Swen.A (Gibe) worm, it comes through email spam and pretends to be a fake Microsoft Patch.

Name: I-WORM.Swen.A

AKA: Gibe.C

Type: Internet Worm

Size: 106496 bytes 

Platform: Win 95/98/ME/NT/2000/XP 

Description:

This worm comes attached to messages of this kind:

Message subject:
Last Microsoft Upgrade
New Microsoft Critical Upgrade

or with other subjects.

Message bodies could also be differents, this is an example of a I-WORM.Swen.A body:

 

  Microsoft   All Products |  Support |  Search |  Microsoft.com Guide 
Microsoft Home  
 

Microsoft Consumer

this is the latest version of security update, the "September 2003, Cumulative Patch" update which eliminates all known security vulnerabilities affecting MS Internet Explorer, MS Outlook and MS Outlook Express as well as three newly discovered vulnerabilities. Install now to maintain the security of your computer from these vulnerabilities, the most serious of which could allow an attacker to run executable on your computer. This update includes the functionality = of all previously released patches.


 System requirements Windows 95/98/Me/2000/NT/XP
 This update applies to MS Internet Explorer, version 4.01 and later
MS Outlook, version 8.00 and later
MS Outlook Express, version 4.01 and later
Recommendation Customers should install the patch = at the earliest opportunity.
How to install Run attached file. = Choose Yes on displayed dialog box.
 How to use You don't need to do = anything after installing this item.

Microsoft Product Support Services and Knowledge Base articles can be found on the Microsoft Technical Support web site. = For security-related information about Microsoft products, please = visit the Microsoft Security Advisor web site, = or Contact Us.

Thank you for using Microsoft products.

Please do not reply to this message. = It was sent from an unmonitored e-mail address and we are unable = to respond to any replies.

The names of the actual companies and = products mentioned herein are the trademarks = of their respective owners.

  Contact Us  |  Legal  |  TRUSTe
  ©2003 Microsoft Corporation. All rights reserved. Terms of Use  |  Privacy Statement |  Accessibility


The attached file could have random names, here're some examples: Q114946.exe, UPGRADE.EXE, 
Q992761.EXE (Patch , Upgrade, Update, Installer, Install, Pack, Q
).

Some messages use the IFRAME technique to be executed automatically, we strongly recommend to upgrade your
Outlook Express version to the latest version available (>6.0 recommended)

Once executed, the worm creates a random-named file inside Windows's system folder, and edits some registry keys to execute that file
at every PC startup.
It aIso creates the following files: Germs0.dbv, Swen1.dat, %PC_NAME%.bat

Periodically, a MAPI32 Exception error pops out, asking for your email credentials.
The user musn't fill in any data, but should only click on CANCEL.

Swen.A worm sometimes create .ZIP or .RAR files containing the worm, and could also spread itself through LAN, Kazaa and mIRC.

20/09/2003 - All rights reserved to TG Soft S.a.s. - http://www.tgsoft.it

Analysis made by: Eng. G. Tonello

Any information published on our site may be used and published on other websites, blogs, forums, facebook and/or in any other form both in paper and electronic form as long as the source is always and in any case cited explicitly “Source: CRAM by TG Soft www.tgsoft.it” with a clickable link to the original information and / or web page from which textual content, ideas and / or images have been extrapolated.
It will be appreciated in case of use of the information of C.R.A.M. by TG Soft www.tgsoft.it in the report of summary articles the following acknowledgment/thanks “Thanks to Anti-Malware Research Center C.R.A.M. by TG Soft of which we point out the direct link to the original information: [direct clickable link]”

Vir.IT eXplorer PRO is certified by the biggest international organisation: