Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe@cygwin.com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin@cygwin.com>
List-Help: <mailto:cygwin-help@cygwin.com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner@cygwin.com
Mail-Followup-To: cygwin@cygwin.com
Delivered-To: mailing list cygwin@cygwin.com
To: cygwin@cygwin.com
From: Pat Brown <pat@ncbrowns.com>
Subject: Re: is "BKDR_HACDEF.M" found in c:\cygwin\bin\cygcrypt-0.dll for real?
Date: Mon, 10 Jan 2005 14:07:37 -0500
Lines: 20
Message-ID: <41E2D279.1000704@ncbrowns.com>
References: <D1AFF63C5E38624EA484C5E94C47B6650171A495@phlexch01.int.gestalt-llc.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Complaints-To: usenet@sea.gmane.org
X-Gmane-NNTP-Posting-Host: user-0c8htvc.cable.mindspring.com
User-Agent: Mozilla Thunderbird 1.0 (Windows/20041206)
In-Reply-To: <D1AFF63C5E38624EA484C5E94C47B6650171A495@phlexch01.int.gestalt-llc.com>
X-IsSubscribed: yes

Laurence G Esmonde wrote:
> We are using Trend Micro's OfficeScan and users at our site started
> having cygcrypt-0.dll quarantined for BKDR_HACDEF.M around 8:15am EST.
> Followed Trend's regedit procedures, but nobody was able to find the
> corresponding registry entries that BKDR_HACDEF.M should have created.  

Several of my colleagues and I have seen the same issues with Office 
Scan, and failed to find any evidence of the described infection using 
Trend's directions.

I tested my home system, which has an up-to-date AVG configuration, and 
it had no complaints.

> Does anybody @ Cygwin have a copy of Trend Micro's software to see if it
> trips up on the master TAR file?

FWIW (probably not much), I also verified that the MD5 sum on my 
"infected" package matched the sum on my mirror (http://mirrors.rcn.net).

Pat


--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

