It’s a mystery

Going to be in full investigation mode today. One of the PC’s here at work, when visiting some website, got 3 different Symantec warnings about Trojan.Trunlow:

The virus warnings said “Access Denied”

But at the same time stamp, Symantec was shutdown, and some of the password stealer .exe’s listed on that page showed up in C:/WINNT/. On the other hand, none of the registry settings were made, and there’s no evidence that it tried to actually send out any information, that I’ve found yet. The IE patch was installed, so in theory, between that being patched and Symantec catching the VBS trojan, none of it should have been allowed to run, but it was.

I suppose it’s time to go ask some questions of the user. I’m sure that won’t provide any real answers. 🙂

Similar Posts

  • Doesn’t get more fun than this

    Yes, since I’m responsible for the “pool” laptops that are available to our attorneys for use outside of the office, and since they’re all Dells, I spent a good part of my Monday checking for laptop battery recalls. Yippee for me! I’ve gotten through about half the laptops we have and haven’t found one yet…

  • OPML challenge..

    Kent and Eric have answered the call from last week and sent me links to their OPML files. I’ve imported them to NewsDesk, pruning as I did it to avoid duplication or just feeds that don’t apply to me. (By the way, nice feature of NewsDesk to let you add channels by loading an OPML…

  • New Gmail features

    I’ve been away from the PC most of the weekend and just catching up now, so you may know about the new Gmail features already, but I just want to say, I’ve been waiting and waiting for the ability to export my contacts, so I’m one happy dude now that it’s here. Tags: Gmail Follow…

  • Morning notes

    For those of you who were interested, I did manage to get home in time last night to do my own packing. 🙂 We’ll be off to West Va. right after work today. I’m not sure if I’ll get around to any updates this weekend, but it is possible. I’m bringing the laptop in hopes…

  • Good morning

    Day 2 of Gnomedex today. Watched Chris get all jazzed about RSS. That was sort of cool. Skipped the Zone Labs session on security because I needed to plug in the laptop. It seems to have some difficulty with being run on battery power. Hope it’s not a sign of more hardware problems! Met JR…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)