PSS Security Response Team Alert - New E-Mail Worm: W32/Swen@MM

SEVERITY: MODERATE
DATE: September 18, 2003
PRODUCTS AFFECTED: Microsoft Outlook, Microsoft Outlook Express, and
Web-based e-mail

**********************************************************************

WHAT IS IT?
W32/Swen@MM spreads via e-mail and network shares. The Microsoft Product
Support Services Security Team is issuing this alert to advise customers to
be on the alert for this virus as it spreads in the wild. Customers are
advised to review the information and take the appropriate action for their
environments.

IMPACT OF ATTACK: Mass Mailing, disabling processes related to security
software such as antivirus and firewall software

TECHNICAL DETAILS:
For additional details on this worm from anti-virus software vendors
participating in the Microsoft Virus Information Alliance (VIA) please visit
the following links:

Network Associates:

http://vil.nai.com/vil/content/v_100662.htm

Trend Micro:

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SWEN.A

Symantec

http://securityresponse.symantec.com/avcenter/venc/data/w32.swen.a@mm.html

Computer Associates:

http://www3.ca.com/virusinfo/virus.aspx?ID=36939

For more information on Microsoft's Virus Information Alliance please visit
this link: http://www.microsoft.com/technet/security/virus/via.asp

Please contact your Antivirus Vendor for additional details on this virus.


PREVENTION:

1. This worm is exploiting a previously patched vulnerability. The
vulnerability exploited is related to the following Microsoft Security
Bulletin:
http://www.microsoft.com/technet/security/bulletin/ms01-020.asp

As always, customers are advised to install the latest security patch for
Internet Explorer. Information on the latest cumulative security patch for
Internet Explorer can be found here:
http://www.microsoft.com/technet/security/bulletin/MS03-032.asp

2. Outlook 2000 post SP2 and Outlook XP SP1 include the most recent updates
to improve the security in Outlook and other Office programs. This includes
the functionality to block potentially harmful attachment types. If you are
running either of these versions, they will (by default) block the
attachment, and you will be unable to open it.

To ensure you are using the latest version of Office click here:
http://office.microsoft.com/ProductUpdates/default.aspx

By default, Outlook 2000 pre SR1 and Outlook 98 did not include this
functionality, but it can be obtained by installing the Outlook E-mail
Security Update. More information about the Outlook E-mail Security Update
can be found here:

http://office.microsoft.com/Downloads/2000/Out2ksec.aspx

Outlook Express 6 can be configured to block access to potentially-damaging
attachments. Information about how to configure this can be found here:

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q291387

Outlook Express all other versions: Previous versions of Outlook Express do
not contain attachment-blocking functionality. Please exercise extreme
caution when opening unsolicited e-mail messages with attachments.

Web-based e-mail programs: Use of a program-level firewall can protect you
from being infected with this virus through Web-based e-mail programs.

RECOVERY:
If your computer has been infected with this virus, please contact your
preferred antivirus vendor or Microsoft Product Support Services for
assistance with removing it.

TECHNET SECURITY LINK:
http://www.microsoft.com/technet/security/virus/alerts/swen.asp

As always please make sure to use the latest Anti-Virus detection from your
Anti-Virus vendor to detect new viruses and their variants.

If you have any questions regarding this alert please contact your Microsoft
representative or 1-866-727-2338 (1-866-PCSafety) within the US, outside of
the US please contact your local Microsoft Subsidiary. Support for virus
related issues can also be obtained from the Microsoft Virus Support
Newsgroup which can be located by clicking on the following link
news://msnews.microsoft.com/microsoft.public.security.virus.

PSS Security Response Team


--
Regards,

Jerry Bryant - MCSE, MCDBA
Microsoft IT Communities

Get Secure! www.microsoft.com/security


This posting is provided "AS IS" with no warranties, and confers no rights.

Re: PSS Security Alert - New E-Mail Worm: W32\Swen@MM by Kerry

Kerry
Thu Sep 18 14:22:58 CDT 2003

I sent my initial copies of this to CA and they replied that it was a new
virus and their EZ-Antivirus signatures would be updated on the 19th
(tomorrow) ... just a little TOO late for some people perhaps!!!

:-(



Re: PSS Security Alert - New E-Mail Worm: W32\Swen@MM by Bill

Bill
Thu Sep 18 14:59:16 CDT 2003

This is going to be true for many folks today, I'm afraid.

AVG DID update today, but I haven't checked what the definitions include.

"Kerry Liles" <kerryliles@rogers.nospam.com> wrote in message
news:%23R0QUthfDHA.944@TK2MSFTNGP11.phx.gbl...
> I sent my initial copies of this to CA and they replied that it was a new
> virus and their EZ-Antivirus signatures would be updated on the 19th
> (tomorrow) ... just a little TOO late for some people perhaps!!!
>
> :-(
>
>



Re: PSS Security Alert - New E-Mail Worm: W32\Swen@MM by Larry

Larry
Thu Sep 18 14:39:11 CDT 2003

Go get the updates now--they are up on the CA site.

--
Larry Samuels MS-MVP (Windows-Shell/User)
Associate Expert
Unofficial FAQ for Windows Server 2003 at
http://home.earthlink.net/~larrysamuels/WS2003FAQ.htm
Expert Zone - www.microsoft.com/windowsxp/expertzone
"Kerry Liles" <kerryliles@rogers.nospam.com> wrote in message
news:%23R0QUthfDHA.944@TK2MSFTNGP11.phx.gbl...
> I sent my initial copies of this to CA and they replied that it was a new
> virus and their EZ-Antivirus signatures would be updated on the 19th
> (tomorrow) ... just a little TOO late for some people perhaps!!!
>
> :-(
>
>



Re: PSS Security Alert - New E-Mail Worm: W32\Swen@MM by Richard

Richard
Thu Sep 18 20:23:15 CDT 2003

Hi,

The latest Norton AntiVirus signature file is dated
9/17/03 and it does not recognize W32.Swen.A@mm. Their
next signature file is due 9/24/03. Symantec suggested I
download a beta signature file, but I doubt many people
will know to do this. I also note that the seurity level
of this is 2 out of 5. This is similar to the response to
the Sobig.F virus, where it took several days before the
antivirus vendors upgraded from "low distribution". I
already have almost as many copies of this virus as
Symantec claims are extant. They only allow you to submit
one suspected infected file to them per day. There seems
to be no way to alert anyone that this is bigger than
advertized. There is no way I can submit copies of the
mail delivery failure notices I am also receiving to find
out what they mean.

Richard
Microsoft MVP Scripting and ADSI
>-----Original Message-----
>Go get the updates now--they are up on the CA site.
>
>--
>Larry Samuels MS-MVP (Windows-Shell/User)
>Associate Expert
>Unofficial FAQ for Windows Server 2003 at
>http://home.earthlink.net/~larrysamuels/WS2003FAQ.htm
>Expert Zone - www.microsoft.com/windowsxp/expertzone
>"Kerry Liles" <kerryliles@rogers.nospam.com> wrote in
message
>news:%23R0QUthfDHA.944@TK2MSFTNGP11.phx.gbl...
>> I sent my initial copies of this to CA and they replied
that it was a new
>> virus and their EZ-Antivirus signatures would be
updated on the 19th
>> (tomorrow) ... just a little TOO late for some people
perhaps!!!
>>
>> :-(
>>
>>
>
>
>.
>

Re: PSS Security Alert - New E-Mail Worm: W32\Swen@MM by Bill

Bill
Thu Sep 18 20:31:28 CDT 2003

Richard--don't worry about it. I am certain that they have both the bounce
messages and the patch one as well.



Re: PSS Security Alert - New E-Mail Worm: W32\Swen@MM by Roger

Roger
Thu Sep 18 21:25:43 CDT 2003

Many AV have issued extra updates by mid afternoon for this.

--
Roger
"Kerry Liles" <kerryliles@rogers.nospam.com> wrote in message
news:%23R0QUthfDHA.944@TK2MSFTNGP11.phx.gbl...
> I sent my initial copies of this to CA and they replied that it was a new
> virus and their EZ-Antivirus signatures would be updated on the 19th
> (tomorrow) ... just a little TOO late for some people perhaps!!!
>
> :-(
>
>



Re: PSS Security Alert - New E-Mail Worm: W32\Swen@MM by Kristofer

Kristofer
Fri Sep 19 04:23:13 CDT 2003

Hi,

You can often download and install the update manually, by going to your AV
software's web site.

--
Regards,
Kristofer Gafvert
http://www.ilopia.com - FAQ & Tutorials for Windows Server 2003, and SQL
Server 2000
Reply to newsgroup only. Remove NEWS if you must reply by email, but please
do not.


"Kerry Liles" <kerryliles@rogers.nospam.com> wrote in message
news:%23R0QUthfDHA.944@TK2MSFTNGP11.phx.gbl...
> I sent my initial copies of this to CA and they replied that it was a new
> virus and their EZ-Antivirus signatures would be updated on the 19th
> (tomorrow) ... just a little TOO late for some people perhaps!!!
>
> :-(
>
>