Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

New Virus

Options
  • 19-09-2003 8:55am
    #1
    Closed Accounts Posts: 40


    I just read on Ireland.com that there is a new virus for microsoft software(nothing new there so)

    Did anyone here anything about his??


Comments

  • Closed Accounts Posts: 494 ✭✭Lukin Black


    Did it give a name? This one - Swen, perhaps? Looks like it's a beeyatch to remove. It's only been included in yesterday's NAV definitions.


  • Closed Accounts Posts: 801 ✭✭✭dod


    Now that does look like a beeeatch


  • Closed Accounts Posts: 40 no1lfcfan


    Thats the one Lukin Black.

    Have downloaded the latest DAT on my systems so I should be covered (fingers crossed)


  • Closed Accounts Posts: 1,008 ✭✭✭Tivoli


    yeah its called W32.Swen.A@mm

    it will look like a patch from microsoft, doupt too many people still fall for that, but it also comes as a message delivery failure.
    i got it in an email 8 times by 7pm yesterday and norton antivirus didnt detect it even after a live update,got it about 80 more times overnight.
    if you run it it asks you to confirm if you want to install it, but whether you say yes or no you infect the pc
    attachement is 106kb,


  • Closed Accounts Posts: 40 no1lfcfan




  • Advertisement
  • Registered Users Posts: 10,339 ✭✭✭✭LoLth


    That NAi site has a link to an Extra.DAT for updating your antivirus (instead of waiting until thursday updates) and a registry cleaner that will remove the entries placed by Swen.


  • Registered Users Posts: 931 ✭✭✭moridin


    To the foredeck matey, there's lootin to be done!


  • Registered Users Posts: 414 ✭✭Paddyo


    Sophos have called this worm W32/Gibe-F


    Paddyo


  • Moderators, Recreation & Hobbies Moderators, Science, Health & Environment Moderators, Technology & Internet Moderators Posts: 91,761 Mod ✭✭✭✭Capt'n Midnight


    you can use the SGET util (somewhere on the CD) to download lastest IDE's - use your favorite schedule app.

    sget.exe http://www.sophos.co.uk/downloads/ide/ides.zip
    Use FC to compare this download with the previous one

    If they are different then You can then use the appropiate program to unzip the update into the sophos folder and then run SETUP.EXE -UPDATE to incorporate the changes

    Note: Two more IDE's since that one....

    19/09/03 13:26 415 YAHA-W.IDE
    18/09/03 17:23 161 ORAGON-A.IDE
    18/09/03 13:22 441 GIBE-F.IDE


  • Registered Users Posts: 414 ✭✭Paddyo


    We had been using the Sget utility which was triggered each time a virus alert came in from Sophos - then ran a central install update.

    Now we are using the Sophos Enterprise Manager and Savadmin to keep our identities up to date - works a treat.

    Paddyo


  • Advertisement
  • Registered Users Posts: 10,339 ✭✭✭✭LoLth


    Slight technical hitch...

    the registry cleaning tool from mcafee for this virus is blocked from access the registry, even in safe mode!

    Anyone know of a removal tool that can be run?


  • Registered Users Posts: 414 ✭✭Paddyo




  • Registered Users Posts: 10,339 ✭✭✭✭LoLth


    thanks paddy0. Looks like it will work.

    Will have a field test on monday morning :)


  • Registered Users Posts: 379 ✭✭Carnate


    22 so far and counting Norton is working overtime, all the same viruses Worm.automat.AHB.


    Sigh usual.. here we go again.


  • Registered Users Posts: 11,987 ✭✭✭✭zAbbo


    i had my 50 machines up to date, Mc Afee Groupshield Manager on the email server as well, only picked up one instance and dealt with it there and then


Advertisement