delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2002/12/14/11:36:12

Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sources.redhat.com/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sources.redhat.com/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com
Message-Id: <5.2.0.9.2.20021214082824.00ff3e48@pop3.cris.com>
X-Sender: rrschulz AT pop3 DOT cris DOT com
Date: Sat, 14 Dec 2002 08:36:02 -0800
To: cygwin AT cygwin DOT com
From: Randall R Schulz <rrschulz AT cris DOT com>
Subject: Re: How did I get it?
In-Reply-To: <3DFB21EF.9030508@mscha.org>
References: <003801c2a350$d2995310$2a83883e AT pomello>
<001d01c2a31a$2c55e8a0$6501a8c0 AT columbus DOT rr DOT com>
<003801c2a350$d2995310$2a83883e AT pomello>
Mime-Version: 1.0

Gentlemen,

This is a little disappointing... The "MovieWorld" virus described at the 
McAfee site (<http://vil.mcafee.com/dispVirus.asp?virus_k=99529>) appears 
to be unknown to Norton AntiVirus. I tried searching the NAV virus 
encyclopedia using both "MovieWorld," "Cygwin," "Cygwin1.dll" and "SUA.BAT" 
(a file listed as essential to the MovieWorld Trojan on the McAfee site) to 
no avail. This despite the date on the McAfee listing is June 4, 2002.

So, it appears those who use Norton AntiVirus will not detect this Trojan.

Randall Schulz
Mountain View, CA USA


At 04:19 2002-12-14, Michael Schaap wrote:
>On 14-Dec-2002 10:11, Max Bowsher wrote:
>>Jack Rose <jrose22 AT columbus DOT rr DOT com> wrote:
>>
>>>Could some tell me how the CYGWIN1.DLL ended up on my computer. It
>>>seems to have just appeared at 3:09am yesterday and I know I wasn't
>>>working at that time.
>>>
>>>Could this have been uploaded to my machine for malicious purposes?
>>>If so, what else should I be looking for, besides a better firewall
>>>and virus detector?
>>>
>>>Any information would be appreciated...
>>
>>Well, someone (apparently not you) installed Cygwin, or a program which uses
>>a cut down Cygwin install to function.
>
>And this could indeed be a virus or worm.  There is at least one that 
>includes cygwin1.dll:
>
>http://vil.mcafee.com/dispVirus.asp?virus_k=99529
>
>I'd certainly check your PC carefully for viruses, if I were you.
>
>  - Michael


--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Bug reporting:         http://cygwin.com/bugs.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019