Security Incidents mailing list archives

Re: homepage worm


From: Kris Boulez <krbou () PGSGENT BE>
Date: Wed, 9 May 2001 08:31:44 +0200

Quoting black-hand (black () WIRETAPPED NET):
Hi,

There is a new VBS worm doing its rounds down here in Australia at the
moment, a lot of virus scanners arnt picking it up. Its not a malicious
payload, but still..

ive put up the email, attachment and payload info here:

http://black.wiretapped.net/homepagevirus.asp

to bypass virus scanners, it does a simple decypher then execute


It's also running around in Europe. Description of this one can be found
at

 http://www.antivirus.com/vinfo/virusencyclo/default5.asp?VName=VBS_HOMEPAGE.A

Kris,


Current thread: