There appears to be some sort of a new AIM exploit/worm/adware-script that advertises the website www.realphx.com. It sets people's AIM profiles to an advertisement for www.realphx.com and it also changes their default homepage in IE to the same thing.. I have no idea what *ELSE* it does. I'm not qualified (what so ever) to figure out exactly what it is or how it works so I figured I'd send this along to the list and hopefully someone will have some expertise in this sort of thing. It appears to take advantage of the Windows Scripting Host or whatever its called.. anyhow you can get all the files that seem to be causing the infections right off the moron's website at: http://www.realphx.com/project/ or http://64.246.11.26/~realphx/project/ or if the idiot happens to be subscribed to BugTraq I'll mirror the files @ http://shell.ltnx.com/realphx. Sorry for the lame format of this email and the lame content, I just can't stand to let AIM crap propagate around the Internet. -- Michael A. Nunes /p at pcmike dot net http://pcmike.net/