Re: New Worm/Variant -- MSDTC32?

From: Jeff Anderson (jeff.anderson_at_usask.ca)
Date: 04/13/04


Date: Tue, 13 Apr 2004 10:22:30 -0600

Jeff Anderson wrote:
> Ant wrote:
>
>> "Jeff Anderson" wrote...
>>
>>
>>> I sent them a sample on Thursday, and they sent out an IDE on Friday
>>> to supposedly provide protection against this variant. It still does
>>> not detect this worm. Here's what Sophos wrote:
>>>
>>> "Name: W32/Agobot-GA [...]"
>>
>>
>>
>> Did you put the IDE in the Sophos Sweep directory? You then need to
>> stop and restart the Sophos services (or reboot).
>>
>> If it then still fails to detect, you should inform Sophos.
>>
>>
>
> We have Sophos configured to update from a Central installation
> Directory (CID) on our server so Sophos has updated from there. The IDE
> is present but not detecting this worm. I will contact Sophos and see
> what's going on.

Ok, so they have finally released an IDE to provide protection. Details can be found here:

http://www.sophos.com/virusinfo/analyses/w32agobotfz.html



Relevant Pages

  • Re: New Worm/Variant -- MSDTC32?
    ... >>I sent them a sample on Thursday, and they sent out an IDE on Friday ... >>to supposedly provide protection against this variant. ... > Did you put the IDE in the Sophos Sweep directory? ...
    (comp.security.misc)
  • TCP/IP Service
    ... this is corrupt by a Trojan. ... Sophos put out an IDE on 2nd July but back up tapes from April to date have ... IDE is published. ...
    (microsoft.public.windows.server.sbs)
  • Sophos "idefetch" script
    ... got three responses right away asking for my script to fetch updated IDE ... files from Sophos' web site. ...
    (FreeBSD-Security)
  • Re: Sophos PureMessage users: how do you handle Exchange 1164 errors ?
    ... argue with Sophos. ... PureMessage logs and show them that when the error 1164 occurs, ... The only choice I have now is to trap errors 1164, kill the Store process ... way to restart IS. ...
    (microsoft.public.windows.server.sbs)
  • A disc read error occurred
    ... I uninstalled Panda then - stupidly forgetting I hadn't immediately rebooted - I installed Sophos. ... Boot from CD: ... Ctrl+Alt+Del to restart ...
    (microsoft.public.win2000.general)

Quantcast