Microsoft "Swen" Worm Squiggles Into Sight
Posted by timothy on Saturday September 20, @06:15PM
from the mmm-wriggling dept.
http://slashdot.org/
http://www.technewsworld.com/perl/story/31632.html
worm
http://securityresponse.symantec.com/avcen....swen.a@mm.html
tool
http://securityresponse.symantec.com/avcen...moval.tool.html
QUOTE
Still, even non-Windows users were affected by the worm's spread, as one TechNewsWorld reader -- a Mac user -- reported receiving more than 250 Swen e-mails in the last day.
MessageLabs chief technology officer Mark Sunner described the worm as highly complex and told TechNewsWorld that although it was first discovered September 14th, it was not seen as a priority, and the threat was not added to updated protection from leading antivirus vendors.
QUOTE
"Initially, this went right under the nose of normal desktop antivirus," Sunner said, endorsing MessageLabs' intercept-and-scan approach over traditional antivirus methods that he claimed do not work. "It's almost inexcusable it went through those vendors."
QUOTE
"It's massively polymorphic," he said. "It randomizes file text, file name and subject with a high degree of polymorphism. Someone really thought about this."
Sunner likened the worm to the original Gibe worm, but said it was written in C++ and also used an SMTP engine, adding to the indications of a highly sophisticated author.