[Dshield] New W32/Swen@MM worm or virus.

Doug White doug at clickdoug.com
Sat Sep 20 00:13:15 GMT 2003

Fortunately no infection - the virus has to go through three layers to get to
me - first on the mail server (started catching all of them after about the
first 10)  then Zone Alarm (changes the file extension on all executable
attachments.) and then Norton when I tried to save a sample it gets deleted.
The high security settings in outlook Express prevented the ones with the iframe
code from executing.

I think the first 10 got through just before the definitions automatically
updated on the server.

Stop spam on your domain, use our gateway!
For hosting solutions http://www.clickdoug.com
Featuring Win2003 Enterprise, RedHat Linux, CFMX 6.1 and all databases.
ISP rated: http://www.forta.com/cf/isp/isp.cfm?isp_id=772
Suggested corporate Anti-virus policy: http://www.dshield.org/antivirus.pdf
If you are not satisfied with my service, my job isn't done!

----- Original Message ----- 
From: "John D." <lists at webcrunchers.com>
To: <list at dshield.org>
Sent: Friday, September 19, 2003 6:34 PM
Subject: [Dshield] New W32/Swen at MM worm or virus.

| Has anyone actually gotten infected with this worm.   If so,  please have them
contact me.   I want to try and find out the patterns in the mail header so I
can Analyse it.
| John
| _______________________________________________
| list mailing list
| list at dshield.org
| To change your subscription options (or unsubscribe), see:

More information about the list mailing list