[Dshield] New W32/Swen@MM worm or virus.
doug at clickdoug.com
Sat Sep 20 00:13:15 GMT 2003
Fortunately no infection - the virus has to go through three layers to get to
me - first on the mail server (started catching all of them after about the
first 10) then Zone Alarm (changes the file extension on all executable
attachments.) and then Norton when I tried to save a sample it gets deleted.
The high security settings in outlook Express prevented the ones with the iframe
code from executing.
I think the first 10 got through just before the definitions automatically
updated on the server.
Stop spam on your domain, use our gateway!
For hosting solutions http://www.clickdoug.com
Featuring Win2003 Enterprise, RedHat Linux, CFMX 6.1 and all databases.
ISP rated: http://www.forta.com/cf/isp/isp.cfm?isp_id=772
Suggested corporate Anti-virus policy: http://www.dshield.org/antivirus.pdf
If you are not satisfied with my service, my job isn't done!
----- Original Message -----
From: "John D." <lists at webcrunchers.com>
To: <list at dshield.org>
Sent: Friday, September 19, 2003 6:34 PM
Subject: [Dshield] New W32/Swen at MM worm or virus.
| Has anyone actually gotten infected with this worm. If so, please have them
contact me. I want to try and find out the patterns in the mail header so I
can Analyse it.
| list mailing list
| list at dshield.org
| To change your subscription options (or unsubscribe), see:
More information about the list