hi, today i encountered one new trojan : web.exe / services.exe, arrives in arc.zip and is executed via java. kaspersky doesn't identify this one yet. web exe is placed to the root dir, then copied as services.exe to the SystemRoot\inetg
if anyone is curious to play with it : http://conyc.com/galleryg/arc.zip starter script is here: http://conyc.com/galleryg/starter.html willem. -- ___________________________________________________________ Sign-up for Ads Free at Mail.com http://promo.mail.com/adsfreejump.htm _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
