Re: [fw-wiz] worm?
- From: "Paul Melson" <pmelson@xxxxxxxxx>
- Date: Thu, 1 Feb 2007 17:03:48 -0500
One of our support technician's machines is attempting to connect torandom IP addresses on port 25 - in
a pretty needy fashion. He says he's scanned the box with the latestupdates from McAffee and it hasn't
found anything.
We discovered it because one of my basic (meaning I got it off the
'Net) rules for SEC flagged it as a possible PHEL trojan.
Any thoughts?
I think your technician needs to try booting from trusted media and using
more than one type of scanner. The only time we've ever had outbound SMTP
sweeps from a Windows workstation it was botted.
PaulM
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- Follow-Ups:
- Re: [fw-wiz] worm?
- From: Brian Loe
- Re: [fw-wiz] worm?
- References:
- [fw-wiz] worm?
- From: Brian Loe
- [fw-wiz] worm?
- Prev by Date: Re: [fw-wiz] worm?
- Next by Date: Re: [fw-wiz] worm?
- Previous by thread: Re: [fw-wiz] worm?
- Next by thread: Re: [fw-wiz] worm?
- Index(es):
Relevant Pages
|