FYI,


 



Thought I'd let everyone know about a new threat that actually got past a 
3-tiered antivirus environment.



 



It is an email with an attachment.  The attachment is a rar file with a 
compressed portable exe file.  The file opens all sorts of nice things like SSL 
connections to the outside to retrieve more nasty stuff and even disables local 
AV products as well as the usual reg changes.  Even local, manual scans were 
unable to detect the threat with the latest dat files.



 



It then tried to email itself and started looking around our network...



 



Needless to say, my system is toast.



 



It got lose while I was dissecting it in a new exe editor.  The editor opened 
IE and tried to display the payload and that's when all he** broke lose.



 



Watch out!



 



Danny


------------------------------------------------------
To unsubscribe:           [EMAIL PROTECTED]
For additional commands:         [EMAIL PROTECTED]
Archive:  http://archives.gnatbox.com/gb-users/

Reply via email to