Code red worm giving false results in NAV CE

From: Brock Campbell (bcampbel@linux.securityfocus.com)
Date: 08/08/01


From: Brock Campbell <bcampbel@linux.securityfocus.com>
To: security-basics@securityfocus.com
Subject: Code red worm giving false results in NAV CE
Date:  Wed, 8 Aug 2001 14:25:50 -0300
Message-Id: <01Aug8.142736cst.115206@ns.ads.ca>

Just ran into this one.

A coworker just asked me about Code Red and said his machine was infected.
He's running WinME so I checked it out a bit further. Turns out the
'infection' is a file with a .gif extension that contains the html for the
'hacked by chinese' defacement. Is this how Symantec is implementing the
scanning for the bug? Or are they just being over cautious/ marketing hype
driven?

Any Ideas.



Relevant Pages

  • Re: Swen harvesting addresses
    ... > Update Download Centre as these are the only Internet ... > NAV seems to have detected all the attempts and I ... > My NAV does not detect any infection on my Computer...is ...
    (microsoft.public.security.virus)
  • Re:Problem solved - Mysterious "Script" pop-up... very concerned... please have a look --
    ... NAV initially did not pick up this infection. ... But, after I downloaded and installed their latest "Beta Definitions", it ... Chris ...
    (microsoft.public.scripting.virus.discussion)
  • Re: Sven
    ... directions for removing the infection. ... If, for example, you have Norton Antivirus installed with the appropriate ... If you retrieve e-mail with NAV e-mail protection activated, ... If you don't have an Antivirus program, get one, install it, configure it ...
    (microsoft.public.security.virus)
  • RE: Swen harvesting addresses
    ... Update Download Centre as these are the only Internet ... NAV seems to have detected all the attempts and I ... My NAV does not detect any infection on my Computer...is ... I have seen here some suggestion that munging one's ...
    (microsoft.public.security.virus)
  • Re: msconfig missing,
    ... This behavior is symptomatic of a viral infection. ... > try to go to msconfig, normally the System Configuration Utility dialogue ... > Also now, when I trry to launch the NAV, it just would not launch. ...
    (microsoft.public.windowsxp.general)