Educause Security Discussion mailing list archives

Re: BlackWorm Addendum


From: Chris Harrington <charrington () NITROSECURITY COM>
Date: Tue, 24 Jan 2006 19:17:59 -0500

For those without commercial IDS / IPS products you can find Snort
signatures to detect infected hosts at:

http://isc.sans.org/diary.php?storyid=1067 

--Chris

--
Christopher Harrington
Chief Technology Officer
nitrosecurity
o: 603.766.8160
c: 603.969.0592
e: charrington () nitrosecurity com
w: www.nitrosecurity.com
skype:chrisharrington



-----Original Message-----
From: RLVaughn [mailto:Randy_Vaughn () BAYLOR EDU] 
Sent: Tuesday, January 24, 2006 6:00 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] BlackWorm Addendum

From field reports the Microsoft Malware removal tool,
Windows-KB890830-V1.12-ENU.exe, does not remove this particular worm.


--
Best Regards,
Randal Vaughn
Professor, Information Systems
Baylor University
(254) 710 4756

Current thread: