Firewall Wizards mailing list archives

sndvol.exe


From: "Randy Garbrick" <garbrir () hotmail com>
Date: Thu, 18 Mar 1999 16:33:06 PST

Has anyone noticed a Trojan horse called sndvol.exe that replaces the 
Win NT/9X sndvol.exe and then does a continuous port scan from inside a 
firewall to multiple outside addresses?  It created a denial of service 
by maxing out the sessions on our Pix.  We're trying to locate the 
source of the executable.


Randy Garbrick

Get Your Private, Free Email at http://www.hotmail.com



Current thread: