Threat Level: green Handler on Duty: Manuel Pelaez

SANS ISC InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
New version of wireshark is available (1.8.4), some security fixes included.

McAfee releases extraDAT for W32/Autorun.worm.aaeb-h

Published: 2012-11-28
Last Updated: 2012-11-28 22:46:20 UTC
by Mark Hofman (Version: 1)
5 comment(s)

McAfee released an extra dat this morning https://kc.mcafee.com/corporate/index?page=content&id=KB76807 for W32/Autorun.worm.aaeb-h

We've received a few emails relating to this, mainly because the formatting on some of the emails wasn't quite what people were expecting.  As far as I can tell it is legit.  I haven't found any evilness in the PDF linked to from the KB (at least there wasn't anything to find when I checked).

The KB also has an updated stinger file to remove the worm from the machine. 

If you have the issue at the moment you may want to apply the DAT, but otherwise you may wish to wait untill it rolls out as part of the normal update cycle.  In the mean time have a read of the KB and associated info and that will give you some info on determining if you have the issue in your network .

If you have been infected the malware guys and gals always enjoy plucking things apart so upload it via the contact form (zip file with a password of infected please).

 

Mark

 

5 comment(s)
ISC StormCast for Wednesday, November 28th 2012 http://isc.sans.edu/podcastdetail.html?id=2968
Diary Archives