N
Netuser 58
Hello Newsreaders,
I made an important discovery about the Swen worm.As
everyone knows, it comes through a false Microsoft email pretending to
be an update patch or something similar. On the face of the message,
the attachment is listed as an exe or pif extension. I wanted a sample
of Swen, so I right clicked on the attachment, but was not given the
option to save it as a file. So I left clicked it (only to access it)
and I got the option to open the file or save it to disk. I chose save
to disk. When I made that choice I got the window that gives you the
choice where to save it AND in the file name box, the file was named
with the extension att - NOT exe or pif!! I have downloaded five
samples of Swen and they all had the att extension. Each one I
downloaded, I accessed it through windows explorer AND NO DETECTION!!
Then I added the extension att to my extension list and accessed it
again - this time my AV program gave me the virus prompt immediately,
identifying the file as Win32/Swen.
So, be sure to add the extension att to your extension list in your
"on access" scanner.
Netuser 58
I made an important discovery about the Swen worm.As
everyone knows, it comes through a false Microsoft email pretending to
be an update patch or something similar. On the face of the message,
the attachment is listed as an exe or pif extension. I wanted a sample
of Swen, so I right clicked on the attachment, but was not given the
option to save it as a file. So I left clicked it (only to access it)
and I got the option to open the file or save it to disk. I chose save
to disk. When I made that choice I got the window that gives you the
choice where to save it AND in the file name box, the file was named
with the extension att - NOT exe or pif!! I have downloaded five
samples of Swen and they all had the att extension. Each one I
downloaded, I accessed it through windows explorer AND NO DETECTION!!
Then I added the extension att to my extension list and accessed it
again - this time my AV program gave me the virus prompt immediately,
identifying the file as Win32/Swen.
So, be sure to add the extension att to your extension list in your
"on access" scanner.
Netuser 58