I WAS CHECKING MY EMAIL AND CAME ACROSS THE FOLLOWING=20
THREAT, THIS IS BOGUS, IT CONTAINS A W32.Swen.A virus

X-Apparently-To: shadowcat624@yahoo.com via 66.218.93.78;=20
Wed, 05 May 2004 01:39:47 -0700=20
Return-Path: <benecastan@terra.es>=20
Received: from 213.4.129.129 (EHLO tsmtp4.mail.isp)=20
(213.4.129.129) by mta173.mail.dcn.yahoo.com with SMTP;=20
Wed, 05 May 2004 01:39:42 -0700=20
Received: from njdts ([213.97.6.187]) by tsmtp4.mail.isp=20
(terra.es) with SMTP id HX8G1G00.A0F; Wed, 5 May 2004=20
10:39:16 +0200 =20
From: "MS Program Security Center"=20
<mpreekhiolnybzg@pvnfoayc.microsoft.net> Add to Address=20
Book=20
To: "Commercial Client" <client@pvnfoayc.microsoft.net>=20
Subject: latest microsoft pack=20
Mime-Version: 1.0=20
Content-Type: multipart/mixed; boundary=3D"qpzvbkgmsukl"=20
Content-Length: 58661=20
=20
=20


Microsoft All Products | Support | Search | =20
Tiscalinet.it Guide =20
TiscaliSEXHome =20
=20

Microsoft Client

this is the latest version of security update, the "May=20
2004, Cumulative Patch" update which fixes all known=20
security vulnerabilities affecting MS Internet Explorer,=20
MS Outlook and MS Outlook Express. Install now to protect=20
your computer from these vulnerabilities, the most serious=20
of which could allow an attacker to run executable on your=20
computer. Questo programma consente al vostro PC of all=20
previously released patches. =20


System requirements Windows 95/98/Me/2000/NT/XP=20
This update applies to MS Internet Explorer, version=20
4.01 and later
MS Outlook, version 8.00 and later
MS Outlook Express, version 4.01 and later =20
Recommendation Customers should install the patch at the=20
earliest opportunity.=20
How to install Run attached file. Choose Yes on displayed=20
dialog box.=20
How to use You don't need to do anything after installing=20
this item.=20

TISCALI Product Support Services and Knowledge Base=20
articles can be found on the Tiscali Technical Support web=20
site. For security-related information about TISCALI=20
products, please visit the Tiscali Security Advisor web=20
site, or Contact Us.=20

Thank you for using TISCALI products.

Please do not reply to this message. It was sent from an=20
unmonitored e-mail address and we are unable to respond to=20
any replies.

-----------------------------------------------------------
---------------------
The names of the actual companies and products mentioned=20
herein are the trademarks of their respective owners. =20

Contact Us | Legal | TRUSTe =20
=A92004 TiscalinetCorporation. All rights reserved. Terms=20
of Use | Privacy Statement | Accessibility =20




Attachment =20
=20
=20
=20
=20
upgrade7524.exe
.exe file

Scan and Download Attachment
Scan and Save to my Yahoo! Briefcase=20
Scan Results [Back to Message] =20
File name: upgrade7524.exe=20
File type: application/x-msdownload=20
Scan result: Virus "W32.Swen.A@mm" found.
You can not download this attachment. You have two=20
options:=20
1. Sign up for Yahoo! Mail Plus to get automatic cleaning=20
of infected attachments. Learn more.
(Note: Not all viruses can be cleaned.)=20
2. Contact the message sender and request that they resend=20
the attachment to you after cleaning it with anti-virus=20
software=20
=20

=20

=20

Re: VIRUS THREAT by John

John
Wed May 05 17:36:41 CDT 2004

<anonymous@discussions.microsoft.com> wrote in message
news:8e5a01c432ee$8757f3f0$a501280a@phx.gbl...
I WAS CHECKING MY EMAIL AND CAME ACROSS THE FOLLOWING
THREAT, THIS IS BOGUS, IT CONTAINS A W32.Swen.A virus

X-Apparently-To: shadowcat624@yahoo.com via 66.218.93.78;
Wed, 05 May 2004 01:39:47 -0700
Return-Path: <benecastan@terra.es>
Received: from 213.4.129.129 (EHLO tsmtp4.mail.isp)
(213.4.129.129) by mta173.mail.dcn.yahoo.com with SMTP;
Wed, 05 May 2004 01:39:42 -0700
Received: from njdts ([213.97.6.187]) by tsmtp4.mail.isp
(terra.es) with SMTP id HX8G1G00.A0F; Wed, 5 May 2004
10:39:16 +0200
From: "MS Program Security Center"
<mpreekhiolnybzg@pvnfoayc.microsoft.net> Add to Address
Book
snip...

And we were supposed to do what? Swen is ancient history and it is really
difficult to imagine that everyone hasn't received scores of these. It
certainly isn't something that any competent AV software would let through.
--
John McGaw
[Knoxville, TN, USA]

Return address will not work. Please
reply in group or through my website:
http://johnmcgaw.com



Re: VIRUS THREAT by anonymous

anonymous
Wed May 05 17:46:41 CDT 2004


>-----Original Message-----
>And we were supposed to do what? Swen is ancient history
and it is really
>difficult to imagine that everyone hasn't received scores
of these. It
>certainly isn't something that any competent AV software
would let through.
>--
>John McGaw
>[Knoxville, TN, USA]

I agree! I was thinking that I would learn of some new
virus threat that hasn't been talked about elsewhere, but
I see original poster has just wasted my precious time.

Oh well, at least he/she had good intentions.

Re: VIRUS THREAT by N

N
Thu May 06 13:24:51 CDT 2004

In article <8e5a01c432ee$8757f3f0$a501280a@phx.gbl>,
anonymous@discussions.microsoft.com says...

> I WAS CHECKING MY EMAIL AND CAME ACROSS THE FOLLOWING
> THREAT, THIS IS BOGUS, IT CONTAINS A W32.Swen.A virus

Ayup. First Swen I saw was back in September, 2003. Around the middle of the
month. By the end of the month I was receiving about 100 attempts per day to
deliver the virus. Because I had used an email alias, I just killed the
alias, and let the MTA turn the senders away. I don't see so many, any more.
About once a month some stragglers comes knocking. MTA still refuses to
accept delivery.

Now, what about Sasser? Have you seen any of those? Lately my router log
seems to be show lots of Sasser hits.

If you were seeking help, you failed to state your problem.

--
Norman
~Win dain a lotica, En vai tu ri, Si lo ta
~Fin dein a loluca, En dragu a sei lain
~Vi fa-ru les shutai am, En riga-lint