Wireshark mailing list archives

Trojans associate with Wireshark, WinPCap, etc


From: gedropi () allmail net
Date: Sun, 01 Nov 2015 08:58:13 -0800


After discovering the attached trojans during a scan on the 30th, I
removed infected files, scrubbed the registry, repeated the scan. Nada. 
Then, I needed to replace the networking tools by downloading fresh
copies of the removed, infected exe files.  Upon downloading various
tools from their respective websites, I repeated the virus scan to be
sure. All newly downloaded exe files were again infected with the same
trojans.

Since all the Wireshark & WinPCap files were affected, I was wondering
if any of you out there have had the same experience?

I hope that someone can help me brainstorm for a fix.  I need to use the
tools of the trade.

Thanks for any ideas.

Attachment: Trojans Oct 30 & Nov 1, 2015.rtf
Description:

___________________________________________________________________________
Sent via:    Wireshark-users mailing list <wireshark-users () wireshark org>
Archives:    https://www.wireshark.org/lists/wireshark-users
Unsubscribe: https://wireshark.org/mailman/options/wireshark-users
             mailto:wireshark-users-request () wireshark org?subject=unsubscribe

Current thread: