Yikes, you can see the *possible* picture forming....
.ANI exploit on web mail server... plus unpatched windows machines:
EXPL_ANICMOO.GEN:
"This is the Trend Micro detection for the specially crafted cursor, animated cursor (.ANI), and icon formats that exploit a vulnerability in the way Windows handles these files. Successfully exploiting the said vulnerability can allow remote users to issue commands on the affected system."
TROJ_ALPIOK.A:
"This Trojan may be downloaded from remote site(s) by other malware. Once connected, it uses its integrated SMTP engine to act as a proxy server and send spam email messages from the mentioned servers."
TSPY_BZUB.A:
"As a BHO, it is able to monitor and collect the user names and passwords that an affected user keys in while browsing through the Internet. It then saves its gathered information, presumably for future retrieval by a remote malicious user. The said user can use the stolen information to access the affected user's account/s."
I hope your wrong about the trojans used
Powered by ZeN