Is anyone else experiencing large amounts of traffic that appears as
Sasser, then turns into an ircbot.trojan named smsc.exe

connecting on port 6667, then performs HUGE amounts of SNMP get
requests? <grin>  I am, and very few people seem to have any

clue what this is...Virus companies are jumping around trying to define
and be first in line with a solution, I just wondered if

anyone on this forum has seen it yet?


ISS sigs triggering thus far are:







(others have been turned off due to sheer volume)




