Re: AIM virus / worm
From: Steven (steven_at_lovebug.org)
Date: 10/28/05
- Previous message: mis_at_seiden.com: "Re: Who is looking for port 2036?"
- In reply to: Michael Gargiullo: "AIM virus / worm"
- Next in thread: Security Pope: "Re: AIM virus / worm"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: "Michael Gargiullo" <mgargiullo@pvtpt.com>, <incidents@securityfocus.com> Date: Thu, 27 Oct 2005 18:39:33 -0400
Yes,
These are some of the very common backdoor/IRC client worms that are
spreading. They probably have slightly different code so they are not
picked up by AV software for a while. They will spread through
AIM/MSN/Yahoo! via messages saying just like you posted.
Steven
----- Original Message -----
From: "Michael Gargiullo" <mgargiullo@pvtpt.com>
To: <incidents@securityfocus.com>
Sent: Thursday, October 27, 2005 4:26 PM
Subject: AIM virus / worm
> Has any one seen this before... Google showed no results...
>
> Instant message from a friend on your buddy list with a link like so...
>
> see this!! http://home.comcast.net/~svyskocil/image0088.com
>
> and
>
> HILARIOUS!! http://home.earthlink.net/~ylee92504/pic0041.com
>
> Symantec corp with defs from yesterday don't detect anything in the com
> file, but it does propagate when executed.
>
>
- Previous message: mis_at_seiden.com: "Re: Who is looking for port 2036?"
- In reply to: Michael Gargiullo: "AIM virus / worm"
- Next in thread: Security Pope: "Re: AIM virus / worm"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]