Re: FollowUp: Worm1800.exe on UnderNet?

From: Ryan Russell (ryanat_private)
Date: Fri Jun 21 2002 - 11:33:50 PDT

  • Next message: Jim Harrison (SPG): "RE: ICMP type 12 packets"

    On Fri, 21 Jun 2002, cw wrote:
    
    > Someone mentioned that Norton picked it up as a trojan, I mentioned,
    > probably not clearly enough though in the original message that it
    > scanned clean. It still does. This is with the up-to-date version of
    > McAfee that I have.
    
    Specifically, they said it identified a piece of it, after it was run on a
    sacraficial box, and had unpacked itself.  Several of the AV vendors will
    now spot portions of mIRC and the like as a possible trojan component.
    
    Of course, spotting it at that point is a bit too late.
    
    					Ryan
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Fri Jun 21 2002 - 13:15:22 PDT