Well isn't that lovely?

iamwiz82

Lifer
Jan 10, 2001
30,772
13
81
A message I just received from CA:

FILE
------------------------------------------------------------------------
winhelp32.exe
------------------------------------------------------------------------
The Windows PE (I386,EXE) file "winhelp32.exe" has been determined to be malicious. Our researchers have analyzed the file and confirmed the result.

Aliases reported by other AV products are listed here:
(Backdoor.Win32.Rbot.gen) (W32.Spybot.Worm)

Researcher comment:
Rbot

CA antivirus products address this malware as follows:
------------------------------------------------------
eTrust Antivirus r8/v7 (Vet Engine)
We will inform you by email ASAP when we have a signature update
available providing detection.

eTrust Antivirus r8/v7 (InoculateIT Engine)
We will inform you by email ASAP when we have a signature update
available providing detection.

========================================================================

Well it's going to be a long day of fixing the shares and services.

And no one has admin rights. :(