[SpamCop.net - protecting the internet through technology]

[SpamCop-List] Re: IPv6?

Glenn Daniels aukword666 at attglobal.net
Wed Jul 7 18:01:18 EDT 2004


"smogmonster" wrote in message
> "Glenn Daniels" wrote
> > What is tcpip6.sys? This driver is not necessarily a standard
> > Windows Service. It could be a trojan, or mail "worm".
>
> In fact, tcpip6.sys is a standard Windows service as of XP, and it was
> also included in betas of Whistler.
>
> http://research.microsoft.com/msripv6/ReadMe.htm
>

smogmonster:
Nice f/up, thanks! Esp. the link is most informative.

I am let us say, reactionary, have not got past Windows 2000
and would not know what you provided.

If I am understanding the "readme", tcpip6.sys is expected
to be passing packets. Howsomeever, SpamPop was not
"seeing" that previously, and it begs the question why
things are different now... Like, is there a chance that
the driver "fingerprint" was altered by an unrecognized
virus? What harm would come of submitting a copy to
SARC for investigation/ confirmation that it is "clean"?

In my experience, my suspicions pay off as often as not
under investigation. I don't endorse reckless paranoia,
but it also isn't healthy to not be a little paranoid where
there are concerns for malicious code: there is an
awful lot of it "out there", and it seems to me that
tcpip6.sys could be targeted for "attack".

Glenn,
"what, me worry?"




More information about the SpamCop-List mailing list