Swen prevention and cure
Summary: The Swen virus masquerades as a new Microsoft patch - find out how to avoid it, and what to do in the case of infection
How it works
One of the ways Swen spreads is to arrive as an email message containing some references to Microsoft or to a new critical patch for Internet Explorer or as a returned email.
To spread via shared network files, Swen leaves copies of itself in the start-up folders found on individual Windows computers connected to the network.
For IRC users, Swen adds a script.ini file to the mIRC program folder. It then spreads to other IRC users.
To infect other P2P users, Swen adds a copy of itself to the shared file directory using a random but intriguing name.
Once the virus is active, it will attempt to shut down working antivirus and personal firewall applications. Swen will appear to download and install a patch directly from Microsoft; in reality, the virus is changing system Registry files on the infected machine. Changes include, for example, the ability to run the virus every time the computer is rebooted.
Prevention
Windows users who have not installed the Internet Explorer patch MS01-020 for the incorrect MIME header flaw should do so now to prevent automatic infection from Swen. In general, do not open attached files in email without first saving them to the hard disk and scanning them with updated antivirus software. Please note that Microsoft does not email security patches to its users. Contact your antivirus vendor to obtain the latest antivirus signature files that include Swen.
Removal
Most antivirus software companies have updated their signature files to include this virus. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see Central Command, Computer Associates, F-Secure, McAfee, Norman, Sophos, Symantec, and Trend Micro.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
Suggestions?
I have reason to believe I'm not infected with the swen virus. But someone who has my email address is, and I'm getting a hundred spam e-mails per hour... I see multiple virus removal tools, but no spam blocker for this worm. Can anyone help me?
Thank you.
Lana Boter
lboter@nyc.rr.com
I never open attachments when i don't know who sent it to me. And I always send the mails to Yahoo to screen for virusses.
Tonight, after reinstalling Windows 98SE i forgot to fix patcheswith Microsoft.
And yes.....Swen hit me. I think the responsibility is also for Microsoft. It should be possible to go to shop where i bought their software to get a updated reliable version of windows 98se.
They produce products with faillures and should be responsible for the damage!
Marchel
The Netherlands
After I got the swen virus I could not receive incoming mail and messages kept ending up in my deleted box.
Guess I should not worry if something is working but any ideas?
I view Juno webmail from a Unix workstation so I doubt that I am infected.
Thanks,
Lynda
First of all I recomend to open another mail
account in www.operamail.com to avoid
junk mail, spam, virus, trojans, etc. I have
not received spam since about two weeks.
I download a "patch" for blaster in the
official website of Microsoft, I supposed that
it is another "patch" for blaster. Also I recomend to download the opera browser
from www.opera.com
I feel embarassed, but not only because
I "install" a virus, but because I use Windows
in my computer, an AMD based that I like
a lot (the hardware), knowing that linux-based
open source OS's are so superior in all the
aspects. I don't think that MAC OS X have so
many virus, trojans, and worms (if they have
important ones).
My last recomendation is to download Stinger of Symantec from: http://securityresponse.symantec.com/avcenter/ venc/data/w32.swen.a@mm.html, run it
download, install and execute zone alert
(download.com), reboot the computer, run
again Stinger and see the "could not be repaired" message and delete it manually.
This virus kind of regenerates, Sometimes
Stinger is infected?!
If you are not happy with Windows, find a
new "better" version, or get MAC OS X or any
other linux-based OS.