MS security Update Virus

From: Richard Mueller (rlmueller_at_ameritech.net)
Date: 09/20/03


Date: Sat, 20 Sep 2003 12:19:49 -0700


Hi,

Good questions. I just spent considerable time cleaning
out my mailbox on a yahoo server. The crazy part is that
the messages are blocked because they look like spam, not
because they infected. Many more infected messages get
through. The ones blocked are kept in a "bulk" folder for
you to review, again, because they might be spam, not
because they are infected. I configured my yahoo account
to no longer block spam, but allow everything to be
downloaded, then immediately deleted from the yahoo
server. This way, my virus software and firewall can deal
with it. Of course, I never even look at any email until I
have disconnected from the Internet, and I never click on
attachment. If in doubt, I save to disk and scan.

The only solution I know is to either review you email
online through the Yahoo site, or turn of the spam blocker
(as I did) so your mailbox on their server doesn't fill up
without you even knowing. Of course, then you must deal
with the mail in your email program.

The virus is W32.Swen.
Microsoft info:
http://www.microsoft.com/technet/treeview/default.asp?
url=/technet/security/virus/alerts/swen.asp

Symantec Info:
http://securityresponse.symantec.com/avcenter/venc/data/w32
.swen.a@mm.html

Two type of messages are infected:

1. Spoofed Microsoft update or patch messages with *.exe
attachment.
2. Mail delivery failure notices. These don't appear to
have an attachment, but have html source code that
attempts to download or run a script. They are infected.

The latest Norton AntiVirus signature file does not
recognize this virus. Download the beta signature file at
this link, which does recognize it.

ftp://ftp.symantec.com/public/english_us_canada/antivirus_d
efinitions/norton_antivirus/beta/symcbetadefsi32.exe

The same thing happened with the Sobig.F virus a few weeks
ago. Most of the mail servers do not recognize the virus.
They block because it looks like spam, or send you mail
delivery failure messages because the addressee is unknown
(not because it's infected). This amazes me.

Richard
Microsoft MVP Scripting and ADSI
>-----Original Message-----
>Hi All,
>I am getting a virus from "xxxx&advisor.ms.com" which
gives some
>security upgrade for windows application. Due to this
virus size, my
>Yahoo free space is exceeding. What I can do, so that
this mails will
>be blocked by yahoo itself. Why yahoo team is not
upgrading there mail
>server with this virus details...
>
>Regards
>Shibu
>.
>



Relevant Pages

  • Re: Its driving me crazy!
    ... on the SBC server. ... When this happens the account is ... If I use a spam blocker, ... it let many spam and virus messages through. ...
    (microsoft.public.security.virus)
  • Re: MS security Update Virus
    ... I am using yahoo mail and not using any other ... automatically get deleted from yahoo server immediately. ... > the messages are blocked because they look like spam, ... my virus software and firewall can deal ...
    (microsoft.public.security)
  • Re: Its driving me crazy!
    ... I fear the next virus will be worse. ... causes me to exceed the 25MB limit on the server. ... it let many viruses and spam through. ... If I use a spam blocker, ...
    (microsoft.public.security.virus)
  • Re: Weird Emails
    ... Yahoo hosts the email server. ... The virus scan is actually done on their server, ... >>Thanks for the info Mike. ...
    (microsoft.public.security)
  • Receving mails with spoof address
    ... my computers are not affected with virus but im ... receiving mail on the server which contains the mail ... ID that is not on my server and i get postmaster ... Do you Yahoo!? ...
    (RedHat)