Security Incidents mailing list archives

Re: FollowUp: Worm1800.exe on UnderNet?


From: Ryan Russell <ryan () securityfocus com>
Date: Fri, 21 Jun 2002 12:33:50 -0600 (MDT)

On Fri, 21 Jun 2002, cw wrote:

Someone mentioned that Norton picked it up as a trojan, I mentioned,
probably not clearly enough though in the original message that it
scanned clean. It still does. This is with the up-to-date version of
McAfee that I have.

Specifically, they said it identified a piece of it, after it was run on a
sacraficial box, and had unpacked itself.  Several of the AV vendors will
now spot portions of mIRC and the like as a possible trojan component.

Of course, spotting it at that point is a bit too late.

                                        Ryan


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: