delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2007/08/16/09:10:05

X-Spam-Check-By: sourceware.org
Message-ID: <46C44C8B.8090202@hones.org.uk>
Date: Thu, 16 Aug 2007 14:09:31 +0100
From: Cliff Hones <cliff AT hones DOT org DOT uk>
User-Agent: Thunderbird 2.0.0.6 (Windows/20070728)
MIME-Version: 1.0
To: cygwin AT cygwin DOT com
Subject: Re: Attack against Cygwin?
References: <000301c7e003$d091d390$2f01a8c0 AT yourvs85n1xobx>
In-Reply-To: <000301c7e003$d091d390$2f01a8c0@yourvs85n1xobx>
X-Spam-Score: -2.6 (--) (knockando.watchfront.net)
X-Spam-Report: knockando.watchfront.net has scanned this email for spam. Results:- BAYES_00=-2.599 (total -2.6, current threshold 4.0)
X-IsSubscribed: yes
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

Martha Adams wrote:
> Hi, I'm a Cygwin user for some time past; and I check
> my machine frequently using Grisoft AVG Free.  On Aug 10 my AVG found
> something called Obfustat.GCD
> (not Obfustated.GCD) which it said had infested
> several files with particular focus on Cygwin.  I have
> Googled on 'Obfustat.GCD' and today one hit came
> up:
> minkara.carview.co.jp/userid/299856/blog/5808766/
> 
> which is in Japanese but Google does a translation
> of sorts.  This apparently was posted Aug 8, and the
> writer mentions Cygwin.
> 
> On Aug 9 my AVG found 'Win32/Polycrypt' as seven
> or so *.dll files including Byte\Byte.dll, CN\CN.dll, and
> EBCDIC\EBCDIC.dll.
> 
> Two attacks in two days, gets my attention.  Does it
> deserve yours, and a general warning?

No - they are almost certainly false positives, and it has already
been noted here.

AVG was reporting Polycrypt and/or Obfustat on various Cygwin files from
Aug 8th to Aug 13th, but the current virus data files seem ok.

-- Cliff

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019