AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?date=2005-03-06
Updated March 7th 2005 01:47 UTC
"We received several reports today of a piece of malware that circulates via Instant Messenger programs. The malware appears as a message from another person with a teaser such as "hot pic!!" or "OMG look at this!!!" Following that line is a URL pointing to a PIF file such as
parishilton.pif
cute.pif
These files are detected by some anti-virus engines as
Backdoor.Win32.IRCBot.y
IM-Worm.Win32.Kelvir.a
Win32/Bropia.Variant!Worm
If a user clicks the link (executes the .pif) then the infected machine will send copies of the link to the user's IM buddies, and could cause additional damage to the user's computer. Removal instructions are available on several AV vendor's web sites."
>>> http://vil.nai.com/vil/stinger/ - v2.5.3 [1,006,087 bytes] (3/01/2005)

- http://isc.sans.org/diary.php?date=2005-03-06
Updated March 7th 2005 01:47 UTC
"We received several reports today of a piece of malware that circulates via Instant Messenger programs. The malware appears as a message from another person with a teaser such as "hot pic!!" or "OMG look at this!!!" Following that line is a URL pointing to a PIF file such as
parishilton.pif
cute.pif
These files are detected by some anti-virus engines as
Backdoor.Win32.IRCBot.y
IM-Worm.Win32.Kelvir.a
Win32/Bropia.Variant!Worm
If a user clicks the link (executes the .pif) then the infected machine will send copies of the link to the user's IM buddies, and could cause additional damage to the user's computer. Removal instructions are available on several AV vendor's web sites."
>>> http://vil.nai.com/vil/stinger/ - v2.5.3 [1,006,087 bytes] (3/01/2005)