lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <000701c38f85$d97965e0$05100e0a@neptune> Date: Fri, 10 Oct 2003 19:25:53 -0400 From: "Michael A. Nunes" <p@...ike.net> To: <bugtraq@...urityfocus.com> Subject: *ADDENDUM* New AIM Expliot/Worm/Adware-script (realphx.com related) The code from the realphx.com appears to put av.exe in C:\ which has a "COMPANY" value of www.digitalmatter.net. When going to www.digitalmatter.net you are informed that the site has no affiliation with www.realphx.com and that if you are infected you should be disinfected momentarily. So.. if you happen to be infected with the realphx.com crap just goto http://digitalmatter.net/fix.hta?.jpg and open it. It appears to work. -- Michael A. Nunes /p at pcmike dot net http://pcmike.net/