RE: [Full-Disclosure] rpc worm

From: Arcturus (arcturus_at_secrev.net)
Date: 08/12/03

  • Next message: Joey: "Re: [Full-Disclosure] DCOM"
    To: "'Jerry Heidtke'" <jheidtke@fmlh.edu>, "'Jordan Wiens'" <jwiens@nersp.nerdc.ufl.edu>, "'Jason Coombs'" <jasonc@science.org>
    Date: Mon, 11 Aug 2003 20:57:04 -0400
    
    

    I am running NAV Corporate Edition 8.00.9374 with Scan Engine 4.1.0.15,
    and Definitions 8/11/2003 rev.19.

    It provides the following upon the scan of the infected zip of
    mblast.exe

    Scan type: Manual Scan
    Event: Virus Found!
    Virus name: W32.Blaster.Worm
    File: C:\Documents and Settings\jnoble\Desktop\msblast.zip>>msblast.exe
    Location: Quarantine
    Computer: LT001-010254
    User: jnoble
    Action taken: Clean failed : Quarantine succeeded :
    Date found: Mon Aug 11 20:53:35 2003

    I recommend a complete update of all scan engines and virus defs...

    Good Luck.

    -
    Jim Noble
    Network & Security Director
    INFO1
    CISSP, CCSE+, CNX

    770-416-6877 x342 (Tel)
    770-355-5049 (Cell)
    404-318-8467 (Pager)

    ===================================
    CONFIDENTIALITY===================================
    This E-mail is confidential. It should not be read, copied, disclosed or
    used
    by any person other than the intended recipient. Unauthorized use,
    disclosure or
    copying by whatever medium is strictly prohibited and may be unlawful.
    If you have
    received this E-mail in error please contact the sender immediately and
    delete
    the E-mail from your system.
    ===================================
    CONFIDENTIALITY===================================
     

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Joey: "Re: [Full-Disclosure] DCOM"

    Relevant Pages

    • Re: virus?
      ... Well there are three parts to every AV application; Kernel, Engine an Signatures. ... The two most important parts are the Engine and Signature files. ... The Kernel is application and OS related and is insignificant for the purpose of Virus ... not needed for vendor scanner infector analysis. ...
      (microsoft.public.win2000.general)
    • Re: Virus affecting search engines
      ... link to a major search engine. ... into the issue we have found that one of our server I.P. ... This virus was made ... >> but if I try a search, an IE error page loads. ...
      (microsoft.public.scripting.virus.discussion)
    • RE: Intellifind bug in IE?
      ... it's the worst form of a virus ... ... try spybot safer-networking.org ... update first before scanning and remove the scum from your ... engine called Intellifind. ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: AVERT Dat Release Notification: 4424 Emergency Dat Files Release
      ... Update and of course there are always new dat files waiting for me to ... > Engine Security Tips from AVERT and the McAfee Security Engine Development ... > used by ALL McAfee Security virus detection and removal products. ...
      (microsoft.public.security.virus)