public inbox for cygwin@cygwin.com
 help / color / mirror / Atom feed
* How did I get it?
@ 2002-12-13 21:26 Jack Rose
  2002-12-14  5:38 ` Max Bowsher
  0 siblings, 1 reply; 7+ messages in thread
From: Jack Rose @ 2002-12-13 21:26 UTC (permalink / raw)
  To: cygwin

Could some tell me how the CYGWIN1.DLL ended up on my computer. It seems to
have just appeared at 3:09am yesterday and I know I wasn't working at that
time.

Could this have been uploaded to my machine for malicious purposes? If so,
what else should I be looking for, besides a better firewall and virus
detector?

Any information would be appreciated...

Thanks

Jack Rose
jjrose@columbus.rr.com


--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Bug reporting:         http://cygwin.com/bugs.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: How did I get it?
  2002-12-13 21:26 How did I get it? Jack Rose
@ 2002-12-14  5:38 ` Max Bowsher
  2002-12-14  5:49   ` Michael Schaap
  2002-12-14  9:31   ` Jack Rose
  0 siblings, 2 replies; 7+ messages in thread
From: Max Bowsher @ 2002-12-14  5:38 UTC (permalink / raw)
  To: Jack Rose, cygwin

Jack Rose <jrose22@columbus.rr.com> wrote:

> Could some tell me how the CYGWIN1.DLL ended up on my computer. It
> seems to have just appeared at 3:09am yesterday and I know I wasn't
> working at that time.
>
> Could this have been uploaded to my machine for malicious purposes?
> If so, what else should I be looking for, besides a better firewall
> and virus detector?
>
> Any information would be appreciated...

Well, someone (apparently not you) installed Cygwin, or a program which uses
a cut down Cygwin install to function.

What is the full path to Cygwin1.dll? If it is in Windows/System(32) or the
equivalent, look in the registry at:

HKLM\SOFTWARE\Cygnus Solutions\Cygwin\mounts v2\/
(NB: the value name is a single forward slash.),
and the corresponding path in HKCU.

The value of that will provide a hint.

Max.


--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Bug reporting:         http://cygwin.com/bugs.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: How did I get it?
  2002-12-14  5:38 ` Max Bowsher
@ 2002-12-14  5:49   ` Michael Schaap
  2002-12-14 11:34     ` Randall R Schulz
                       ` (2 more replies)
  2002-12-14  9:31   ` Jack Rose
  1 sibling, 3 replies; 7+ messages in thread
From: Michael Schaap @ 2002-12-14  5:49 UTC (permalink / raw)
  To: Jack Rose; +Cc: cygwin

On 14-Dec-2002 10:11, Max Bowsher wrote:
> Jack Rose <jrose22@columbus.rr.com> wrote:
> 
> 
>>Could some tell me how the CYGWIN1.DLL ended up on my computer. It
>>seems to have just appeared at 3:09am yesterday and I know I wasn't
>>working at that time.
>>
>>Could this have been uploaded to my machine for malicious purposes?
>>If so, what else should I be looking for, besides a better firewall
>>and virus detector?
>>
>>Any information would be appreciated...
> 
> 
> Well, someone (apparently not you) installed Cygwin, or a program which uses
> a cut down Cygwin install to function.
> 

And this could indeed be a virus or worm.  There is at least one that 
includes cygwin1.dll:

http://vil.mcafee.com/dispVirus.asp?virus_k=99529

I'd certainly check your PC carefully for viruses, if I were you.

  - Michael


--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Bug reporting:         http://cygwin.com/bugs.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: SPAM - Re: How did I get it?
  2002-12-14  5:38 ` Max Bowsher
  2002-12-14  5:49   ` Michael Schaap
@ 2002-12-14  9:31   ` Jack Rose
  1 sibling, 0 replies; 7+ messages in thread
From: Jack Rose @ 2002-12-14  9:31 UTC (permalink / raw)
  To: Max Bowsher, cygwin

Thanks for the response Max.

I tried running regedit. It pops up and then immediately closes itself, the
same thing happens when I attempt to run msconfig.

I found cygwin1.dll in the \windows directory. I also found a new exe -
shiver.exe. A search of the web indicates that this is a trojan.


----- Original Message -----
From: Max Bowsher
To: Jack Rose ; cygwin@cygwin.com
Sent: Saturday, December 14, 2002 4:11 AM
Subject: SPAM - Re: How did I get it?


Jack Rose <jrose22@columbus.rr.com> wrote:

> Could some tell me how the CYGWIN1.DLL ended up on my computer. It
> seems to have just appeared at 3:09am yesterday and I know I wasn't
> working at that time.
>
> Could this have been uploaded to my machine for malicious purposes?
> If so, what else should I be looking for, besides a better firewall
> and virus detector?
>
> Any information would be appreciated...

Well, someone (apparently not you) installed Cygwin, or a program which uses
a cut down Cygwin install to function.

What is the full path to Cygwin1.dll? If it is in Windows/System(32) or the
equivalent, look in the registry at:

HKLM\SOFTWARE\Cygnus Solutions\Cygwin\mounts v2\/
(NB: the value name is a single forward slash.),
and the corresponding path in HKCU.

The value of that will provide a hint.

Max.


--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Bug reporting:         http://cygwin.com/bugs.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: How did I get it?
  2002-12-14  5:49   ` Michael Schaap
@ 2002-12-14 11:34     ` Randall R Schulz
  2002-12-16  5:14     ` Robert Collins
  2002-12-19 17:47     ` SPAM - " Jack Rose
  2 siblings, 0 replies; 7+ messages in thread
From: Randall R Schulz @ 2002-12-14 11:34 UTC (permalink / raw)
  To: cygwin

Gentlemen,

This is a little disappointing... The "MovieWorld" virus described at the 
McAfee site (<http://vil.mcafee.com/dispVirus.asp?virus_k=99529>) appears 
to be unknown to Norton AntiVirus. I tried searching the NAV virus 
encyclopedia using both "MovieWorld," "Cygwin," "Cygwin1.dll" and "SUA.BAT" 
(a file listed as essential to the MovieWorld Trojan on the McAfee site) to 
no avail. This despite the date on the McAfee listing is June 4, 2002.

So, it appears those who use Norton AntiVirus will not detect this Trojan.

Randall Schulz
Mountain View, CA USA


At 04:19 2002-12-14, Michael Schaap wrote:
>On 14-Dec-2002 10:11, Max Bowsher wrote:
>>Jack Rose <jrose22@columbus.rr.com> wrote:
>>
>>>Could some tell me how the CYGWIN1.DLL ended up on my computer. It
>>>seems to have just appeared at 3:09am yesterday and I know I wasn't
>>>working at that time.
>>>
>>>Could this have been uploaded to my machine for malicious purposes?
>>>If so, what else should I be looking for, besides a better firewall
>>>and virus detector?
>>>
>>>Any information would be appreciated...
>>
>>Well, someone (apparently not you) installed Cygwin, or a program which uses
>>a cut down Cygwin install to function.
>
>And this could indeed be a virus or worm.  There is at least one that 
>includes cygwin1.dll:
>
>http://vil.mcafee.com/dispVirus.asp?virus_k=99529
>
>I'd certainly check your PC carefully for viruses, if I were you.
>
>  - Michael


--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Bug reporting:         http://cygwin.com/bugs.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: How did I get it?
  2002-12-14  5:49   ` Michael Schaap
  2002-12-14 11:34     ` Randall R Schulz
@ 2002-12-16  5:14     ` Robert Collins
  2002-12-19 17:47     ` SPAM - " Jack Rose
  2 siblings, 0 replies; 7+ messages in thread
From: Robert Collins @ 2002-12-16  5:14 UTC (permalink / raw)
  To: Michael Schaap; +Cc: cygwin

[-- Attachment #1: Type: text/plain, Size: 424 bytes --]

On Sat, 2002-12-14 at 23:19, Michael Schaap wrote:


> 
> And this could indeed be a virus or worm.  There is at least one that 
> includes cygwin1.dll:
> 
> http://vil.mcafee.com/dispVirus.asp?virus_k=99529
> 
> I'd certainly check your PC carefully for viruses, if I were you.

I wonder if they included the source :}.

Rob
-- 
---
GPG key available at: http://users.bigpond.net.au/robertc/keys.txt.
---

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: SPAM - Re: How did I get it?
  2002-12-14  5:49   ` Michael Schaap
  2002-12-14 11:34     ` Randall R Schulz
  2002-12-16  5:14     ` Robert Collins
@ 2002-12-19 17:47     ` Jack Rose
  2 siblings, 0 replies; 7+ messages in thread
From: Jack Rose @ 2002-12-19 17:47 UTC (permalink / raw)
  To: Michael Schaap; +Cc: cygwin

I'd like to thank all who responded to my query. The cygwin1.dll was indeed
used maliciously. I dumped my McAfee and purchased Norton System Works 2003.
It took me a total of 3 days get my infected machine back up and running.
Most of the difficultly came from the fact that the "worm" and its
associated programs remapped a lot of the registry.

Norton identified 3 worms with the main culprit being Backdoor.SubSeven22.
Two of the exe's being used were wlhsnrbw.exe and avill.exe.

Again - many thanks!

Jack Rose

----- Original Message -----
From: Michael Schaap
To: Jack Rose
Cc: cygwin@cygwin.com
Sent: Saturday, December 14, 2002 7:19 AM
Subject: SPAM - Re: How did I get it?


On 14-Dec-2002 10:11, Max Bowsher wrote:
> Jack Rose <jrose22@columbus.rr.com> wrote:
>
>
>>Could some tell me how the CYGWIN1.DLL ended up on my computer. It
>>seems to have just appeared at 3:09am yesterday and I know I wasn't
>>working at that time.
>>
>>Could this have been uploaded to my machine for malicious purposes?
>>If so, what else should I be looking for, besides a better firewall
>>and virus detector?
>>
>>Any information would be appreciated...
>
>
> Well, someone (apparently not you) installed Cygwin, or a program which
uses
> a cut down Cygwin install to function.
>

And this could indeed be a virus or worm.  There is at least one that
includes cygwin1.dll:

http://vil.mcafee.com/dispVirus.asp?virus_k=99529

I'd certainly check your PC carefully for viruses, if I were you.

  - Michael



--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Bug reporting:         http://cygwin.com/bugs.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2002-12-20  0:47 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2002-12-13 21:26 How did I get it? Jack Rose
2002-12-14  5:38 ` Max Bowsher
2002-12-14  5:49   ` Michael Schaap
2002-12-14 11:34     ` Randall R Schulz
2002-12-16  5:14     ` Robert Collins
2002-12-19 17:47     ` SPAM - " Jack Rose
2002-12-14  9:31   ` Jack Rose

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).