[32053] in bugtraq

home help back first fref pref prev next nref lref last post

*ADDENDUM* New AIM Expliot/Worm/Adware-script (realphx.com related)

daemon@ATHENA.MIT.EDU (Michael A. Nunes)
Sat Oct 11 15:26:36 2003

Message-ID: <000701c38f85$d97965e0$05100e0a@neptune>
Reply-To: "Michael A. Nunes" <p@pcmike.net>
From: "Michael A. Nunes" <p@pcmike.net>
To: <bugtraq@securityfocus.com>
Date: Fri, 10 Oct 2003 19:25:53 -0400
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit

The code from the realphx.com appears to put av.exe in C:\ which has a
"COMPANY" value of www.digitalmatter.net.  When going to
www.digitalmatter.net you are informed that the site has no affiliation with
www.realphx.com and that if you are infected you should be disinfected
momentarily.

So.. if you happen to be infected with the realphx.com crap just goto
http://digitalmatter.net/fix.hta?.jpg and open it.  It appears to work.

--
Michael A. Nunes
/p at pcmike dot net
http://pcmike.net/


home help back first fref pref prev next nref lref last post