Re: New Worm/Variant -- MSDTC32?

From: Jeff Anderson (jeff.anderson_at_usask.ca)
Date: 04/12/04


Date: Mon, 12 Apr 2004 12:41:45 -0600

Ant wrote:
> "Jeff Anderson" wrote...
>
>
>>I sent them a sample on Thursday, and they sent out an IDE on Friday
>>to supposedly provide protection against this variant. It still does
>>not detect this worm. Here's what Sophos wrote:
>>
>>"Name: W32/Agobot-GA [...]"
>
>
> Did you put the IDE in the Sophos Sweep directory? You then need to
> stop and restart the Sophos services (or reboot).
>
> If it then still fails to detect, you should inform Sophos.
>
>

We have Sophos configured to update from a Central installation Directory (CID) on our server so
Sophos has updated from there. The IDE is present but not detecting this worm. I will contact
Sophos and see what's going on.



Relevant Pages

  • Re: New Worm/Variant -- MSDTC32?
    ... >> Did you put the IDE in the Sophos Sweep directory? ... >> stop and restart the Sophos services. ...
    (comp.security.misc)
  • TCP/IP Service
    ... this is corrupt by a Trojan. ... Sophos put out an IDE on 2nd July but back up tapes from April to date have ... IDE is published. ...
    (microsoft.public.windows.server.sbs)
  • Sophos "idefetch" script
    ... got three responses right away asking for my script to fetch updated IDE ... files from Sophos' web site. ...
    (FreeBSD-Security)
  • Re: [Full-Disclosure] VX: Old worm in new shoes (AntiQFX)
    ... >> Only Sophos detects this file as AntiQFX.F variant. ... Bitdefender detects it also, and so does ClamAV right now, in the last ...
    (Full-Disclosure)
  • Re: New Worm/Variant -- MSDTC32?
    ... > to supposedly provide protection against this variant. ... > not detect this worm. ... Did you put the IDE in the Sophos Sweep directory? ...
    (comp.security.misc)

Quantcast