I think i have a Virus :)
#1
Posted 02 July 2003 - 08:59 AM
I opened it, nothing happened. Me drive spun, as per but nothing happened. Btw, i had my Outlook open at the time.
Now, i open outlook to check my e-mails... I send/recieve and get an e-mail from my freind named 'application' same as the one i got form my mums work collegue. With the same file attached 'your_details.zip'.
I scanned with Norton and it picked up nothing (i have 2002 but not with updated definitions as i havent re-newed my subscription). Any ideas what this thing is?!
That actual filename in the .zip file is 'details.pif'.
Cheers, Flash.
#2
Posted 02 July 2003 - 09:08 AM
DETAILS.PIF-1AA87EDF.pf
Location: C:\WINDOWS\Prefetch
Size: 12KB
Type: PF File
Date Modified: 02/07/2003 15:32 (Today).
Hellllllllllp me
#3
Posted 02 July 2003 - 09:20 AM
#4
Posted 02 July 2003 - 09:22 AM
#5
Posted 02 July 2003 - 09:24 AM
#6
Posted 02 July 2003 - 09:25 AM
#7
Posted 02 July 2003 - 09:27 AM
C-Girl, on Jul 2 2003, 04:24 PM, said:
Spreading in e-mails
The worm spreads itself in e-mails. The infected message is composed by the worm from different, randomly selected subjects, a fixed message body and different, randomly selected attachment names. The worm's file is sent inside a ZIP archive attached to an infected message.
The worm has the following subjects hardcoded in its body:
referer.pif
004448554.pif
re.document.pif
new_document.pif
submited.pif
Screensaver.scr
movie.pif
Applications.pif
Application.pif
Your application
Re: Re: Document
Re: Re: Application ref. 003644
Re: Documents
Re: Screensaver
Re: Submited (Ref: 003746)
Re: Movies
Re: Movie
Re: Application
The worm has the following attachment names hardcoded in its body. The worm's executable file name that is sent in an archive is given in brackets:
Movie.zip (Movie.pif)
screensaver.zip (sky_world.scr)
document.zip (document.pif)
application.zip (application.pif)
your_details.zip (details.pif)
However, so far we only saw messages with the following characteristics:
Subject:
Re: Application
or
Re: Movie
Body:
Please see the attached zip file for details.
Attachment:
your_details.zip
The attachment contains the worm's file with DETAILS.PIF name. The fact that the worm uses only 2 subjects and 1 attachment name indicates that the randomizing routine of the worm has a bug.
Here's a screeshot of an infected message sent by the worm:
#8
Posted 02 July 2003 - 09:32 AM
http://securityresponse.symantec.com/avcen...sobig.e@mm.html
Symantec does have a removal tol you can download...
#9
Posted 02 July 2003 - 10:02 AM
#11
Posted 02 July 2003 - 11:31 AM
#12
Posted 02 July 2003 - 01:10 PM
Thanks anyways.
#13
Posted 02 July 2003 - 01:11 PM
#14
Posted 02 July 2003 - 02:17 PM
I've gotten the SOBIG, the YAHA, the KLEZ, and the LOVELETTER viruses!
#15
Posted 02 July 2003 - 04:14 PM
'dear mary'
its john hre, hope you had great fun the other night on the beach strole...eh? lol
#16
Posted 02 July 2003 - 04:24 PM
EDIT: Whoops! Just read flash's post. He mentionted it.
#17
Posted 02 July 2003 - 04:42 PM
HandyBuddy, on Jul 2 2003, 06:24 PM, said:
EDIT: Whoops! Just read flash's post. He mentionted it.
Why exactly would someone want to make a virus that stops spreading on July 12th? People can just advance their clocks...Can't they?
#18
Posted 03 July 2003 - 07:51 AM
#19
Posted 03 July 2003 - 08:31 AM
my parents got a one from the dr denmark or something lol.. and it stuffed there hdd
#20
Posted 03 July 2003 - 08:35 AM
On my old machine, thats another story, mostly hacks on that with my little hack wars, lol.



Help


Back to top









