请输入您要查询的百科知识:

 

词条 Swen (computer worm)
释义

  1. Infection

     Self-installation  Autostart 

  2. References

{{infobox computer virus
| Fullname =Swen
| Common name =Swen worm
| Technical name =Win32/Swen
| Type =Computer worm
| Subtype =Mass mailer
| Aliases =
  • Win32/Swen.worm.106496 (AhnLab)
  • W32/Swen.A@mm (Authentium Command)
  • I-Worm/Swen.A (AVG)
  • Win32/Swen.A@mm (BitDefender)
  • Win32/Swen.A.Worm (CA)
  • Win32/Swen.A (ESET)
  • Email-Worm.Win32.Swen (Kaspersky)
  • W32/Swen@MM (McAfee)
  • W32/Swen.A@mm (Norman)
  • W32/Gibe.C.worm (Panda)
  • W32/Gibe-F (Sophos)
  • Email-Worm.Win32.Swen (Sunbelt Software)
  • W32.Swen.A@mm (Symantec)
  • WORM_SWEN.A (Trend Micro)
  • I-Worm.Swen.A1 (VirusBuster)

| Isolation =September 18, 2003
| Filesize =106-496 bytes
| OSes =Windows 95 to Windows XP
| Image =
}}

Swen is a mass mailing computer worm written in C++. It sends an email which contains the installer for the virus, disguised as a Microsoft Windows update, although it also works on P2P filesharing networks, IRC and newsgroups' websites. It was first analyzed on September 18, 2003, however, it might have infected computers before then. It disables firewalls and antivirus programs.

Infection

Self-installation

The virus first sends itself via email with an attachment, posing as an update for Windows. The attachment can have a .com, .scr, .bat, .pif, or .exe file extension. If its file name starts with the letters P, Q, U, or I, It displays a fake Microsoft Update dialogue box, asking if the user wants to install a Microsoft Security Update with the two choices "Yes" and "No". If the user presses "Yes", it displays a fake progress bar while installing the fake update. When finished, it displays another dialogue box saying: Microsoft Internet Update Pack This has been successfully installed. The malware then re-executes itself, followed by yet another dialogue box saying: Microsoft Security Update Pack This update does not need to be installed on this system. If the user chooses "No", the malware will still install itself silently in the background. Next, it checks for certain criteria by opening another dialogue box, prompting the user for their email address, username, password, SMTP server, and their POP3 server. After completing the said fields, the worm then makes a copy of itself in the C:\\Windows folder as .exe. The virus finally moves all information to the copy and terminates.

Autostart

The worm creates the following registry entry to execute upon startup:

HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\

CurrentVersion\\Run\\ = ".exe autorun"

References

  1. Trend Micro Threat Encyclopedia | WORM_SWEN.A
  2. BitDefender Virus Information for Swen.A@mm

2 : Email worms|Hacking in the 2000s

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/9/25 12:22:06