Jump to content

Recommended Posts

Hi, a program that has been on our server for years came back as Spyware.Lokibot. It has never scanned as Spyware before, so I am curious as to why it would suddenly start scanning as such. On the hourly scan, it came back two hours in a row, then didn't appear anymore. It is these two files

Name Type Category Status Path
Spyware.LokiBot File Malware Quarantined C:\PROGRAM FILES (X86)\SPICEWORKS\NMAP-5.61-SPICEWORKS-SETUP.EXE
Spyware.LokiBot File Malware Quarantined

C:\PROGRAM FILES\WINPCAP\RPCAPD.EXE

 and the programs installed are

Nmap 5.61-Spiceworks   05/19/2016  
Spiceworks Desktop 7.5.00087 05/19/2016 Spiceworks, Inc.
WinPcap 4.1.2-Spiceworks 4.1.0.2001 05/19/2016 CACE Technologies

 

Please let me know if this was a false positive, or possibly caused by an update to Spiceworks (not sure if it updated automatically or anything). 

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.