funsec mailing list archives

Re: anyone having network infections with these?


From: Paul Ferguson <fergdawgster () gmail com>
Date: Wed, 17 Nov 2010 14:11:00 -0800

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Do you have a link to the VirusTotal results?

- - ferg

On Wed, Nov 17, 2010 at 12:09 PM, RandallM <randallm () fidmail com> wrote:

This week been hit by a this:

dwm.exe, shell.exe, svhost

fortunetly I use deepfreeze and doesnt effect system but I usuall thaw
the user profile out for ease of use. But it is storing these now in
the application area and come back after the reboots.

is being spoted by 17 of 47 on virus total. Just have had a rash of
these this week and cant yet find from where ...they all dont remember
where or what they were doing.



--
been great, thanks
RandyM
a.k.a System
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.5.3 (Build 5003)

wj8DBQFM5FLtq1pz9mNUZTMRAqlJAJ0SDCIVEPF+xhKZtPdUAVSni2Z/xgCeLMDP
XyTM58dsDoGSc5xcfxwvETI=
=WEXH
-----END PGP SIGNATURE-----



-- 
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawgster(at)gmail.com
 ferg's tech blog: http://fergdawg.blogspot.com/

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: