Is anyone else experiencing large amounts of traffic that appears as Sasser, then turns into an ircbot.trojan named smsc.exe
connecting on port 6667, then performs HUGE amounts of SNMP get requests? <grin> I am, and very few people seem to have any clue what this is...Virus companies are jumping around trying to define and be first in line with a solution, I just wondered if anyone on this forum has seen it yet? ISS sigs triggering thus far are: MSRPC_LSASS_Bo TCP_Network_Scan MSRPC_LSASS_Request_Detected Microsoft_Windows_Shell_Banner (others have been turned off due to sheer volume) Thanks, Erin _______________________________________________ ISSForum mailing list [EMAIL PROTECTED] TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum To contact the ISSForum Moderator, send email to [EMAIL PROTECTED] The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.
