Re: Unusual registry entries

From: Jasmine (jasmine.chuaat_private)
Date: Fri Jun 20 2003 - 06:59:35 PDT

  • Next message: Kester, Kelly: "RE: sdbot variant and port 55808 activity"

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    I can't find much between the linkage of Forger & RedTeam, but I think they 
    are memory resident viruses. 
    
    http://www.avp.ch/avpve/newexe/windows/redteam.stm
    http://www.viruslist.com/eng/viruslist.html?id=809
    
    You may want to scan for viruses on your machine. 
    
    On Friday 20 June 2003 04:14, btraquerat_private wrote:
    > Today, while installing an app on a 98 box, we noticed that the user name
    > and organization that Windows was registered to was quite unusual.  The
    > registry key, HKLM-->Software-->Microsoft-->Windows-->CurrentVersion showed
    > the following:
    >
    > RegisteredOwner:  Forger
    > RegisteredOrganization:  RedTeam Art & Dev Lab
    >
    >
    > Have any of you ever seen or heard of anything like this before?
    >
    > A search on Google only brought up four hits when I searched for redteam
    > +forger.    Had no luck using any other search.  Found some light info
    > about 2 viruses that had one or the other in the name, but couldn't any
    > definitive info about either.
    >
    > No unusual apps/processess "appear" to be installed/running and nothing
    > unusual appeared during a review of the system, but this is still very
    > interesting...
    >
    > If you have any info about this it would be greatly appreciated!!
    >
    > Thanks!
    > Gene
    >
    > ---------------------------------------------------------------------------
    >- Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the
    > world's premier technical IT security event! 10 tracks, 15 training
    > sessions, 1,800 delegates from 30 nations including all of the top experts,
    > from CSO's to "underground" security specialists.  See for yourself what
    > the buzz is about! Early-bird registration ends July 3.  This event will
    > sell out. www.blackhat.com
    > ---------------------------------------------------------------------------
    >-
    
    - -- 
    Jasmine Chua
    Security Engineer
    
    SecureCiRT Pte Ltd
    Blk 750C Chai Chee Road
    #04-01 Technopark@ChaiChee
    Singapore 469003
    Tel: 6243 6800 DID: 6243 6802
    Fax: 6441 5119
    
    "Without change, something sleeps inside us, and seldom awakens.  The
    sleeper must be awaken." -- Duke Leto Atreides
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.2 (GNU/Linux)
    
    iD8DBQE+8xNPNgvTa7Hj2AURAo1CAJ9tSYYKGTRZJUM+tMXXDXhQAy5m6wCeOweH
    n6/tJ8SCYtJoKA375J6kf6I=
    =EiGp
    -----END PGP SIGNATURE-----
    
    
    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
    world's premier technical IT security event! 10 tracks, 15 training sessions, 
    1,800 delegates from 30 nations including all of the top experts, from CSO's to 
    "underground" security specialists.  See for yourself what the buzz is about!  
    Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Sat Jun 21 2003 - 11:54:24 PDT