Honeypots mailing list archives

Re: Sebek-WIN32 v3.0.4


From: "Blarnum, Seamus" <crpyt0k1d () yahoo com>
Date: Tue, 1 Jul 2008 11:38:26 -0700 (PDT)

One of the best practices we've done in the past is load an old AV engine and ensure it is not updating with new 
signatures. Anyone getting on your hp is sure to look for AV running in an attempt to shut-it down. 

So, I would recommend keeping it on your system. We happen to see more people looking for AV than Sebek in our sensors.


Seamus


--- On Tue, 6/17/08, forensicist () gmail com <forensicist () gmail com> wrote:

From: forensicist () gmail com <forensicist () gmail com>
Subject: Sebek-WIN32 v3.0.4
To: honeypots () securityfocus com
Date: Tuesday, June 17, 2008, 6:03 AM
I have scanned Sebek-WIN32 v3.0.3 & Sebek-WIN32 v3.0.4
but both are infected and AV detected it as a Malware.
Also, when I restarted my PC1 after installation of
Sebek-WIN32 v3.0.3 and restarted my PC2 after installation
of Sebek-WIN32 v3.0.4, BLUE screen error occur.

I am using  Win 2003 server Enterprise Edition with Sp2 and
HoneyNet CD-ROM roo-1.4.hw-20080423134017.

Please help me regarding this problem.

Your urgent and helpful response will be highly
appreciated.


      


Current thread: