[Snort-sigs] Malware/Spyware

Stef stefmit at ...2420...
Mon Aug 23 12:40:08 EDT 2004

Could it be related to an earlier full-discloure posting:

Hi List, Possible new malware makes startup entries and copies itself
to the windows folder this is where it was found, creates a
CurruntPowerProfile reg startup key with a value of
Rundll32.exe,powrprof.dll,LoadCurrentPwrScheme2.exe cant find anything
else that it is doing except that it is written in VB anyone willing
to have a look at it ? the files are attached as they are just ~ 40 KB
 -aditya ( simply ren *.txt to *.exe ) ?!?

.... but we wouldn't have signatures for it, would we? ... so maybe
just a coincidence ...


On Mon, 23 Aug 2004 13:34:42 -0500, Matthew Jonkman <matt at ...2436...> wrote:
> We're seeing a more than triple the normal number of new spyware
> infections today. I wonder if anyone else is seeing the same?
> Matt

More information about the Snort-sigs mailing list