Re: reports of DCOM worm on the loose...Report #4a

From: Russ (Russ.Cooper_at_RC.ON.CA)
Date: 08/14/03

  • Next message: Schmidt, Tobias E: "Re: GPO blaster scripts -- http://www.winona.edu/its/downloads/msblast.htm"
    Date:         Wed, 13 Aug 2003 18:08:15 -0400
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Ok, wanted to provide some information regarding GriSoft AVG and LovSAN.

    I spoke with people at GriSoft who vehemently denied their AV was using anything as lame as I suggested. I checked again with the reporter, who had sent me the files, and that person is unsure how the files got labeled as cleaned. That person did say that the program did not report them as infected, only that they thought they had been cleaned. Since I don't use the product, I assumed that person recognized the cleaned files as cleaned by GriSoft.

    Anyway, I sent the files to GriSoft and they say there's no indication they were cleaned by GriSoft AVG, or that they were ever infected or could be detected as infected.

    So, bottom line, my apologies for my harsh statements...;-] I have firmly slapped myself upside the head!

    Cheers,
    Russ - NTBugtraq Editor

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Are You "Certifiable"? Summer's Hottest Certification Just Got HOTTER!

    With a growth rate exceeding 110%, the TICSA security practitioner
    certification is one of the hottest IT credentials available. And now, for
    a limited time, you can save 33% off of the TICSA certification exam! To
    learn more about the TICSA certification, and to register as a TICSA
    candidate online, just go to

    http://www.trusecure.com/offer/s0100/

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo


  • Next message: Schmidt, Tobias E: "Re: GPO blaster scripts -- http://www.winona.edu/its/downloads/msblast.htm"

    Relevant Pages

    • Re: Alert: Microsoft Security Bulletin - MS03-039
      ... The way that Microsoft patched the new RPC Part II vulnerability ... Summer's Hottest Certification Just Got HOTTER! ... To learn more about the TICSA certification, ...
      (NT-Bugtraq)
    • WHERE ARE NT4 OLD PASSWORDS STORED
      ... Sorry if this bores many of you (being an NT4 question), ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • Firewalls and DCOM
      ... Never underestimate the lengths to which your users will inadvertently go through to infect a network;)" ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • DCOM worm analysis report: W32.Blaster.Worm
      ... A Bugtraq user has already pointed out that a worm has been ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • Something changing DNS server settings
      ... When I looked in the registry of one of the affected computers, ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)