Swen worm disguised as critical patch
Thursday September 18, 2003
Also known as Gibe.F, the Swen worm spreads via email, KaZaA, and IRC. Swen attempts to disable security software running on infected systems and modifies the system registry to ensure it is run prior to various executables. As is the case with the Dumaru worm, Swen emails can be disguised as a Microsoft security bulletin. Others are disguised as bounced email messages.
Example of Swen email | Sophos description
Example of Swen email | Sophos description


No comments yet. Leave a Comment