View Full Version : Do not open "Latest Microsoft Upgrade" type emails


Belle
26-09-2003, 21:21
My lovely mother fell foul of this virus and thus it came to me, but I was in the end just sufficiently alarmed not to open it but to check on it.
This is what I found
Hope I have saved at least one computer's life
It took mum three hours to mend her PC.
Appliesonly to PC users I imagine, rather than Apple Macintoshes

************

Swen' worm poses as security patch


ZDNet UK
September 18, 2003, 17:50 BST

Antivirus experts fear a new Windows worm could fool many into installing it, because of its legitimate appearance

Antivirus companies are warning of a new Windows worm that has the potential to spread quickly because it appears to be a legitimate security update from Microsoft.

For information on how to combat the worm (assuming you have already opened an email from these people), you will need to go onto Google and do a search for the name of the worm because I forgot to note the name of the website where I got all this from.

The Swen worm, known technically as I-Worm.Swen, W32/Swen.A@mm or W32/Gibe@MM.e, affects Windows 95, Windows NT and all newer versions, and spreads via email and through IRC, Kazaa and local area networks. It uses a vulnerability in Internet Explorer to execute directly from an email message, according to F-Secure. It also attempts to disable firewall and antivirus software. The worm first appeared in the wild on Thursday last week.

Windows users are still reeling from a series of damaging virus attacks that have caused chaos in recent weeks, partly due to the large number of Internet-connected PCs that have not patched known vulnerabilities.

One of the emails Swen uses to spread is a professional-looking message that appears to come from "MS Technical Assistance", and contains a notification of a "September 2003, Cumulative Patch", along with the virus attachment. Microsoft does not spread updates via email.

When executed, the worm continues to pose as a security update, launching a message windows that states: "This will install Microsoft Security Update. Do you wish to continue?" If the user clicks "Yes" the worm shows a fake installation dialogue box, but also installs invisibly if the "No" button is pressed.

Swen installs various files to ensure that it is launched every time the system boots up. It also disables the user's ability to edit the Registry.

Users are advised not to launch attachments. Symantec, F-Secure, Sophos, Network Associates and others have updated the definitions in their anti-virus software to prevent Swen infections.

Jon
26-09-2003, 21:24
:lol: we all fall for stoopid things i did with microsoft patch :? anyone got a hard drive for free i can have plz plz lol

alchresearch
26-09-2003, 21:36
Anyone who's owned a computer for more than a couple of years knows full well that Microsoft don't provide *any* support to it's users, especially emails!

Moon Maiden
26-09-2003, 22:54
I thought it a tad suspicious and deleted a tonne of them

Moon

t020
27-09-2003, 00:47
I have to delete these stupid emails too. I know Microsoft wouldn't email me as they don't even have my address - as if I would register an....... otherwise acquired copy of XP. Besides, the patch has a dodgy name and no icon, and the whole things is just obvious.

Rich
09-08-2008, 18:51
I've been getting a LOT of emails claiming to be from admin@microsoft.com lately about an "update" to IE7, pfft.. I don't even use IE7 a great deal now that I have kind of defected to Firefox 3 (well I did for about 3 weeks, till FF became slow and annoying so I went back to IE)

nobby71
09-08-2008, 19:06
I've been getting a LOT of emails claiming to be from admin@microsoft.com lately about an "update" to IE7, pfft.. I don't even use IE7 a great deal now that I have kind of defected to Firefox 3 (well I did for about 3 weeks, till FF became slow and annoying so I went back to IE)

You have probably been owned pal :hihi:

Rich
09-08-2008, 19:25
You have probably been owned pal :hihi:

Um, what?! :loopy:

nobby71
10-08-2008, 09:47
Um, what?! :loopy:

Quite clearly, its you that doesn't understand Rich!

Space
10-08-2008, 10:04
Hahaha.. Have you seen the original date of this thread??

nobby71
10-08-2008, 10:09
Hahaha.. Have you seen the original date of this thread??

Good innit :hihi:

Space
10-08-2008, 10:13
It's like picking up a 5 year old copy of the Daily Mail to read! :P

alchresearch
10-08-2008, 19:29
Maybe Rich created a new thread but the mods merged it with an old one?

bizzle
10-08-2008, 19:31
Thanks for the warning :thumbsup:

melthebell
10-08-2008, 19:33
bizzle i think youd have had one by now