X-Spam-Check-By: sourceware.org Message-ID: <46C44C61.7070602@hones.org.uk> Date: Thu, 16 Aug 2007 14:08:49 +0100 From: Cliff Hones User-Agent: Thunderbird 2.0.0.6 (Windows/20070728) MIME-Version: 1.0 To: cygwin AT cygwin DOT com Subject: Re: Attack against Cygwin? References: <000301c7e003$d091d390$2f01a8c0 AT yourvs85n1xobx> In-Reply-To: <000301c7e003$d091d390$2f01a8c0@yourvs85n1xobx> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-Spam-Score: -2.6 (--) (knockando.watchfront.net) X-Spam-Report: knockando.watchfront.net has scanned this email for spam. Results:- BAYES_00=-2.599 (total -2.6, current threshold 4.0) X-IsSubscribed: yes Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com Delivered-To: mailing list cygwin AT cygwin DOT com Martha Adams wrote: > Hi, I'm a Cygwin user for some time past; and I check > my machine frequently using Grisoft AVG Free. On Aug 10 my AVG found > something called Obfustat.GCD > (not Obfustated.GCD) which it said had infested > several files with particular focus on Cygwin. I have > Googled on 'Obfustat.GCD' and today one hit came > up: > minkara.carview.co.jp/userid/299856/blog/5808766/ > > which is in Japanese but Google does a translation > of sorts. This apparently was posted Aug 8, and the > writer mentions Cygwin. > > On Aug 9 my AVG found 'Win32/Polycrypt' as seven > or so *.dll files including Byte\Byte.dll, CN\CN.dll, and > EBCDIC\EBCDIC.dll. > > Two attacks in two days, gets my attention. Does it > deserve yours, and a general warning? No - they are almost certainly false positives, and it has already been noted here. AVG was reporting Polycrypt and/or Obfustat on various Cygwin files from Aug 8th to Aug 13th, but the current virus data files seem ok. -- Cliff -- Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple Problem reports: http://cygwin.com/problems.html Documentation: http://cygwin.com/docs.html FAQ: http://cygwin.com/faq/