Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: New Trojan????

New Trojan????

From: Dave Woods <dave_at_TECHWEAVERS.NET>
Date: Tue, 31 Oct 2000 12:28:50 -0700

One of our computers here recently became infected with something I have
never seen before.

When the computer starts up (winME) it opens up 2 copies of the
FreeExtractor prog that exctracts the following files:
mirc.ini
mirc2.ini
mirc3.ini
pri.ini
20139.txt
gates.txt
temp.exe
temp2.exe
whvlxd.dat
temp.scr

gates.txt contains a lot of ip's / domains in it that look to be possibly
infected hosts that this "program" is creating as some of them are isp
accounts ie port200.hs.ip.com
temp.scr does not run (says not a valid win32 app)

I have attached the files in a zip with a password of pass101

If anyone has seen or knows what this is or how to remove it let me know.

Sincerely,
David Woods
Techweavers Inc.
dave_at_techweavers.net
www.techweavers.net
Phone: (780)-423-3952
Fax: (780)-432-3220

  • application/x-zip-compressed attachment: unkown_zip
Received on Nov 01 2000
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos