lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <a50eeaa105012621182064e7a9@mail.gmail.com>
From: worried at gmail.com (Mike Bailey)
Subject: spoolcll.exe - new worm being distributed via
	mysql vulnerability?

Aloha,

Earlier tonight, i was sitting here at home doing some normal
browsing, and work and my firewall alerted me that a program called
spoolcll.exe was attempting to open up a port which i cannot remember
now.

i tried killing it, but it just came back, over and over again each
time spawning itselfs on a new port.

Registry says the worm created a service called "evmon", it cannot be
paused or stopped, but it can be disabled.

The only information about this worm on google is a discussion at the
following url: http://forums.whirlpool.net.au/forum-replies.cfm?t=291921&p=1
they are beginning to determinthat it is being distributed via a hole
in mysql.

Do any of you know anything about this? Thanks in advance.


-- 
Love,
Mike Bailey

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ