UPDATE: 15/03/05
The swine has yet another set of varients, http://securityresponse.symantec.com/av ... vir.g.html
This one hides behind verysexy.pif and http:// [domain removed]/~dentonhome/x.x
http://securityresponse.symantec.com/av ... vir.h.html
This one hides behind toosexy.pif and http:// [domain removed].xihosting.info
http://securityresponse.symantec.com/av ... vir.b.html
This one sends out the message [Link to a Web site on the home.earthlink.net domain] lol! see it! u'll like it
Once the link is clicked on it attempts to download c:\dumprep.exe
http://securityresponse.symantec.com/av ... vir.a.html
The worm arrives in a Windows Messenger window with a link to the file cute.pif.
Also sends out this message Message:
omg this is funny!
[Link to the jose. rivera4.home.att.net domain]
Once again don't open them lol, this thing will wreck havoc on your system if you let it.
yours in randomness!
RG
VIRUS THREAT - UPDATE
- RandomGoth
- Moderator
- Posts: 200
- Joined: Fri Oct 10, 2003 1:06 am
- Location: Morpeth, Northumberland
- Contact:
- RandomGoth
- Moderator
- Posts: 200
- Joined: Fri Oct 10, 2003 1:06 am
- Location: Morpeth, Northumberland
- Contact: