Security Incidents mailing list archives

Strange servicepack.exe file (not service.exe) found.


From: Chip Mefford <cmefford () avwashington com>
Date: Tue, 16 Dec 2003 13:29:09 -0500

Running in the task manager on a windows 98 box on
our lan. The machine was misbehaving badly yesterday
morning. IE 5.5 was broken, will not browse anything,
even a local file. Mozilla 1.5 works fine. The machine
has been flattened and is being reloaded with Win2K.

This machine was screwed down as tight as we could make
it and still have it be useful. It was used by staff
that had no dedicated workstations to access our webmail
and such things.

I know nothing about reverse engineering binary executables.
Strings output showed some concerning lines.

I've posted the file "servicepack.exe" in zipped and
tarred formats both at this url.

http://www.eruditium.org/cmefford/securityfocus/




---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: