|
From: S.A. Birl <sbirl@temple.edu>
Date: Thu Sep 02 2004 - 10:16:30 EDT
(Un)Fortunately, I am not allowed to distribue the exe.
Does anyone know how it infects?
On Sep 1, Harlan Carvey (nospam-keydet89@yahoo.com.ns) typed:
FD: Where in the Registry did you find it? Which key(s)?
There were about 6 Registry enties in the HKLM section. I dont have the
We ran TCPview on the compromised machine and watched it connect to an IRC
On Sep 1, Todd Towles (nospam-toddtowles@brookshires.com.ns) typed:
FD: I see one other post about it here..
That URL is the same one I came across yesterday via Google.
A copy of it has been sent to Symantec.
On Sep 1, Joe Stewart <nospam-jstewart@lurhq.com.ns> typed:
FD: We saw an Rbot variant spreading on August 23 with the same exe
http://virusscan.jotti.dhs.org/ lists msrtwd.exe as backdoor.sdbot.gen
_______________________________________________
This archive was generated by hypermail 2.1.8 : Thu Sep 02 2004 - 11:01:17 EDT |
Custom Search
|