Results 1 to 6 of 6

Thread: Is it Swen or isn't it?

Hybrid View

  1. #1
    belfry Guest

    Is it Swen or isn't it?

    I have been getting the fake Microsoft Update and "returned" e-mails exactly
    like the the Swen virus, but I have downloaded from Symantec and others
    their scanning program and ran it. And they all say I do not have the
    Win32.Swen.A virus. Yet I still am being bombarded with these "returned
    messages" and MS Update notices, all with that 106K size attachment!

    Even F-Prot says my coimputer is clean. Can someone help?



  2. #2
    Little Johnny Guest

    Re: Is it Swen or isn't it?

    You don't have the virus until you open the att.
    If you open it Norton will stop and tell you.

    "belfry" <belfry@insightbb.com> wrote in message
    news:aGRbb.131260$mp.66667@rwcrnsc51.ops.asp.att.n et...
    > I have been getting the fake Microsoft Update and "returned" e-mails

    exactly
    > like the the Swen virus, but I have downloaded from Symantec and others
    > their scanning program and ran it. And they all say I do not have the
    > Win32.Swen.A virus. Yet I still am being bombarded with these "returned
    > messages" and MS Update notices, all with that 106K size attachment!
    >
    > Even F-Prot says my coimputer is clean. Can someone help?
    >
    >




  3. #3
    Ken Russell Guest

    Re: Is it Swen or isn't it?

    That's not correct Little Johnny. In some cases it will activate automatically without the user opening the attachment.

    Yet another Internet virus pretending to be a patch from Microsoft is spreading quickly on the Internet. Swen (w32.swen@mm, also known as Gibe) uses the subject line to entice Windows users to open the attachment. In some cases, the virus will execute automatically.

    --
    Ken Russell

    "Little Johnny" <missb93@hotmail.com> wrote in message news:vn0in0ofeedsf9@corp.supernews.com...
    | You don't have the virus until you open the att.
    | If you open it Norton will stop and tell you.
    |
    | "belfry" <belfry@insightbb.com> wrote in message
    | news:aGRbb.131260$mp.66667@rwcrnsc51.ops.asp.att.n et...
    | > I have been getting the fake Microsoft Update and "returned" e-mails
    | exactly
    | > like the the Swen virus, but I have downloaded from Symantec and others
    | > their scanning program and ran it. And they all say I do not have the
    | > Win32.Swen.A virus. Yet I still am being bombarded with these "returned
    | > messages" and MS Update notices, all with that 106K size attachment!
    | >
    | > Even F-Prot says my coimputer is clean. Can someone help?
    | >
    | >
    |
    |

  4. #4
    Sharky Guest

    Re: Is it Swen or isn't it?

    In message <3f710233$0$18592$afc38c87@news.optusnet.com.au> "Ken
    Russell" <rusty@theseams.com.au> wrote:

    >This is a multi-part message in MIME format.
    >
    >------=_NextPart_000_0014_01C38297.E536C3F0
    >Content-Type: text/plain;
    > charset="Windows-1252"
    >Content-Transfer-Encoding: quoted-printable


    Ken, please don't post html to Usenet groups. The subject matter of
    this thread should be enough to convince people to disable html
    content in their news AND mail clients.

    Do it for the children, man! ;-)


  5. #5
    Ken Russell Guest

    Re: Is it Swen or isn't it?

    OOPS! Sorry about that kids ;-)

    --
    Ken Russell

    "Sharky" <sharky@hellsgate.corg> wrote in message
    news:2782nvg77pi4oevfsse6057lmfocclvsqb@news.alt.n et...
    | In message <3f710233$0$18592$afc38c87@news.optusnet.com.au> "Ken
    | Russell" <rusty@theseams.com.au> wrote:
    |
    | >This is a multi-part message in MIME format.
    | >
    | >------=_NextPart_000_0014_01C38297.E536C3F0
    | >Content-Type: text/plain;
    | > charset="Windows-1252"
    | >Content-Transfer-Encoding: quoted-printable
    |
    | Ken, please don't post html to Usenet groups. The subject matter of
    | this thread should be enough to convince people to disable html
    | content in their news AND mail clients.
    |
    | Do it for the children, man! ;-)
    |



  6. #6
    Jay T. Blocksom Guest

    Re: Is it Swen or isn't it?

    On Tue, 23 Sep 2003 06:24:06 GMT, in <alt.privacy.spyware>, "belfry"
    <belfry@insightbb.com> wrote:
    >
    > I have been getting the fake Microsoft Update and "returned" e-mails
    > exactly like the the Swen virus,

    [snip]

    Not "exactly like the the Swen virus"... It *is* the Swen virus.

    > ...but I have downloaded from Symantec and others
    > their scanning program and ran it. And they all say I do not have the
    > Win32.Swen.A virus.

    [snip]

    Good for you. But that has NOTHING to do with getting bombed by all the
    morons out there who *are* infected.

    > Yet I still am being bombarded with these "returned
    > messages" and MS Update notices, all with that 106K size attachment!
    >

    [snip]

    Yep, that's Swen all right.

    As a point of reference, my mail server has killed ~900 copies of it to
    date, *not* counting the estimated ~4,000 delivery attempts that my various
    static and DNSbl-based blocks have prevented from getting that far. The
    good news (sort of) is that it seems to be slowing down somewhat -- instead
    of ~50/hour, attempts are now down to maybe ~20/hour, with only 2-3 of them
    getting through to the AV scanner, which kills them on sight.

    > Even F-Prot says my coimputer is clean.

    [snip]

    As noted above, that's not relevant.

    > Can someone help?
    >

    [snip]

    Only your ISP, and the ISPs of the idiots whose systems are sending the crap
    -- both of which *should* be filtering it ALL out, by now. ***** at them.

    --

    Jay T. Blocksom
    --------------------------------
    Appropriate Technology, Inc.
    usenet01[at]appropriate-tech.net


    "They that can give up essential liberty to obtain a little temporary
    safety deserve neither liberty nor safety."
    -- Benjamin Franklin, Historical Review of Pennsylvania, 1759.

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    NOTE: E-Mail address in "From:" line is INVALID! Remove +SPAMBLOCK to mail.
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Unsolicited advertising sent to this E-Mail address is expressly prohibited
    under USC Title 47, Section 227. Violators are subject to charge of up to
    $1,500 per incident or treble actual costs, whichever is greater.
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •