C
col_klink
Here is a weird one.
Stinger was the only one to catch it.
NOD32, Norton, AVG and F-Protect all missed it on deep scan settings.
Backdoor-JZ trojan found in c:\agent\data\000005DE.DAT\000000d3d.EML\Parish_
Hilton.scr (yes Parish is spelled wrong I know).
If I browse the file with wordpad I find this:
This is a multi-part message in MIME format
--=_NextPart_2rfkindysadvnqw3nerasdf
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
Parish Hilton having sex
--=_NextPart_2rfkindysadvnqw3nerasdf
Content-Type: application/octet-stream;
name="Parish_Hilton.scr"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="Parish_Hilton.scr"
And a whole bunch of ASCII stuff after it including many other normal things
that he seems to have downloaded like *.mp3's etc.
Is this a false positive?
The dates on that file are from about a month ago and while he might have
downloaded something back then it appears gone now but the leftover record of
what was downloaded seems to be in the DAT file and is triggering Stinger.
Any ideas?
Comments?
TIA
Stinger was the only one to catch it.
NOD32, Norton, AVG and F-Protect all missed it on deep scan settings.
Backdoor-JZ trojan found in c:\agent\data\000005DE.DAT\000000d3d.EML\Parish_
Hilton.scr (yes Parish is spelled wrong I know).
If I browse the file with wordpad I find this:
This is a multi-part message in MIME format
--=_NextPart_2rfkindysadvnqw3nerasdf
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
Parish Hilton having sex
--=_NextPart_2rfkindysadvnqw3nerasdf
Content-Type: application/octet-stream;
name="Parish_Hilton.scr"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="Parish_Hilton.scr"
And a whole bunch of ASCII stuff after it including many other normal things
that he seems to have downloaded like *.mp3's etc.
Is this a false positive?
The dates on that file are from about a month ago and while he might have
downloaded something back then it appears gone now but the leftover record of
what was downloaded seems to be in the DAT file and is triggering Stinger.
Any ideas?
Comments?
TIA