27 Sep
2000
27 Sep
'00
2:43 p.m.
On Wed, 27 Sep 2000, Bill Becker wrote:
Speaking of the internet and the way it operates, is anyone else seeing a large number of random hosts scanning through their address space using TCP on port 139?
Bill
we've seen similar scans here at UCB, and have traced a number of them to a win32 trojan variously named {note.com,Qaz.Trojan,QAZ.worm,TROJ_QAZ.A, Trojan/Notepad,W32.HLLW.Qaz.A}. if you're so inclined, you can test for this by telnetting to port 7597 on the machine that scanned you. http://vil.nai.com/villib/dispVirus.asp?virus_k=98775 for details. ken
8870
Age (days ago)
8870
Last active (days ago)
0 comments
1 participants
participants (1)
-
ken lindahl