Re: Interesting little piece of malware...

"Chris Norton" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
>Further, what do I tel management ... when
> they want to know how it got on here in the first place ?

Really it would be hard to tell how it got on your computers there without
knowing the setup of your network, is everything behind a central firewall
etc. It's possible a student with an infected laptop connected to the
network and it spread that way, or maybe someone checked their email and got
it etc. There are several ways for worms/viruses etc. to sneak past
firewalls, all it takes is a human "host" to carry them past.

As for how to clean it out follow the instructions here for R-BOT:
http://www.sophos.com/virusinfo/analyses/w32rbotei.html

--
Chris Norton
UAT Student Software Engineering Network Defense
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.