ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
Latvian Microtik Router Infector
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
There is a rather nasty piece of malware found infecting routers made by a company in Latvia named Microtik. The malware appears to perform several different functions. In case we have some users from that part of the world or that have a Microtik router, below is an MDB signature for the malware. Copy the signature to a Notepad file, name it Sigfile.mdb (or add it to an existing MDB file), and put it in the ClamWin DB folder. Be sure not to save it as a text file--keep it named Sigfile.mdb--nothing else after the .mdb. You should normally delete a MDB signature after a couple of weeks because they get out-of-date, but keep this signature, as this malware takes advantage of a vulnerability in Microtik routers.

143872:e8e53214fb3f513be459816884e7bb38:Win.Trojan.Agent-101218.1520

Regards,
View user's profileSend private message
Latvian Microtik Router Infector
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic