Office of Information Technology
Home

Calendar

Map
Home
Computing

Library

Search

Security: How-To Guides

Security Home Statistics Virus/AntiVirus Policies &tc How-To Guides Get Our Attention

Quick Find

Get Moving


Get Help

Submit an online Remedy Work Order

Send email to helpdesk@umbc.edu
Gibe-F / Swen / Swen.A Worm (09-18-2003)

Summary

Affects:

All Windows Operating Systems
Internet Explorer versions 5.01, 5.5

Type: Worm
Threat: Run code of attacker's choice;
Typically replicates via email and network shares, IRC, and Kazaa
Fix:

McAfee with DAT 4294 (or greater)

Download and install appropriate patches, then reboot

Incorrect MIME Header Can Cause IE to Execute E-mail Attachment

Patch for Internet Explorer 5.01 and 5.5 Outbound Link

Current Cumulative Patch for Internet Explorer (updated 09.08.2003)

All versions except Microsoft Internet Explorer 6.0 for Windows Server 2003 Outbound Link

Microsoft Internet Explorer 6.0 for Windows Server 2003 Outbound Link

Return to Top


Official Releases

Vendor Reports: Gibe-F / Swen

McAfee's report Outbound Link

F-Secure's description Outbound Link
TrendMicro's details Outbound Link
Sophos' s analysis Outbound Link
Symantec's security response Outbound Link
Microsoft's Official Announcements & Press Releases

TechNet PSS Security Response Team Alert - New E-Mail Worm: W32/Swen@MM (updated: 09.18.2003) Outbound Link

Related CVE Entries

Incorrect MIME Header Can Cause IE to Execute E-mail Attachment: CVE-2001-0154 (assigned:05-07-2001) Outbound Link

What to Do Next

Update McAfee DAT to most recent available
Try a stand-alone removal tool if you are infected:
McAfee's AVERT Stinger®
A "stand-alone utility used to detect and remove specific viruses" including W32/Sobig, W32/SQLSlammer.worm, and W32/Swen@MM
Instructions, Download, and FAQ Outbound Link
F-Secure's Swen Disinfectant Outbound Link
"Please make sure you read the SWENTOOL.TXT file before using the disinfection tool.

Please note that the tool will only disinfect local infection of Swen worm. It will not disinfect your e-mail databases from infected messages."

Instructions and Download Outbound Link



OIT Security: Footer
NOTE: " Outbound Link" Indicates a link to an external (non-UMBC)

Last modified: 9/24/2003

Office of Information Technology • Main Office: ECS 125 • Phone: 410-455-3838 • Email: oit@umbc.edu