At around 3pm EST all of the Windows 98 boxes at my company suddenly turned their proxy settings on (we don't use a proxy) and set their proxy server to: cache.mycompany.com (substitute mycompany with the name of mycompany) and port 3128. Now i know port 3128 is a Squid proxy port, so i guess that makes sense, but has anyone ever seen anything like this before? the few win2k boxes are fine, as are the linux boxes. Is there a trojan or something like that where the payload changes proxy settings? or is it something else entirely? thanks! dave ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
This archive was generated by hypermail 2b30 : Sat Jul 21 2001 - 15:05:46 PDT