MSFN Forum: I think i have a Virus :) - MSFN Forum

Jump to content


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

I think i have a Virus :) Rate Topic: -----

#1 User is offline   Flash 

  • Flash has entered the building
  • PipPipPip
  • Group: Members
  • Posts: 482
  • Joined: 21-May 02

Posted 02 July 2003 - 08:59 AM

Right, i opened up an e-mail from my mums work collegue, it was a win zip file with a file format .pif inside it. I was asked to try and open it, at first i thought it was a Windows 3.1 format .pif so tried opening it.

I opened it, nothing happened. Me drive spun, as per but nothing happened. Btw, i had my Outlook open at the time.

Now, i open outlook to check my e-mails... I send/recieve and get an e-mail from my freind named 'application' same as the one i got form my mums work collegue. With the same file attached 'your_details.zip'.

I scanned with Norton and it picked up nothing (i have 2002 but not with updated definitions as i havent re-newed my subscription). Any ideas what this thing is?!

That actual filename in the .zip file is 'details.pif'.

Cheers, Flash.


#2 User is offline   Flash 

  • Flash has entered the building
  • PipPipPip
  • Group: Members
  • Posts: 482
  • Joined: 21-May 02

Posted 02 July 2003 - 09:08 AM

I just searched my Hard Drive for any files named 'detail.pif'. I found one:

DETAILS.PIF-1AA87EDF.pf

Location: C:\WINDOWS\Prefetch

Size: 12KB

Type: PF File

Date Modified: 02/07/2003 15:32 (Today).

Hellllllllllp me :)

#3 User is offline   C-Girl 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 458
  • Joined: 09-June 03

Posted 02 July 2003 - 09:20 AM

.pif? You utter dumbass :)! Anyone who had barin doesn't open .pif attachments! youve landed yerself a virus, lemme see if i can look it up.

#4 User is offline   zivan56 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 318
  • Joined: 15-June 02

Posted 02 July 2003 - 09:22 AM

http://www.symantec.com/avcenter/venc/data...son.c.worm.html might be the one...

#5 User is offline   C-Girl 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 458
  • Joined: 09-June 03

Posted 02 July 2003 - 09:24 AM

You have sobig.e

http://www.europe.f-...s/sobig_e.shtml

#6 User is offline   C-Girl 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 458
  • Joined: 09-June 03

Posted 02 July 2003 - 09:25 AM

Delete your address book, quick! ive just read it fowards it self on!

#7 User is offline   C-Girl 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 458
  • Joined: 09-June 03

Posted 02 July 2003 - 09:27 AM

C-Girl, on Jul 2 2003, 04:24 PM, said:



Spreading in e-mails

The worm spreads itself in e-mails. The infected message is composed by the worm from different, randomly selected subjects, a fixed message body and different, randomly selected attachment names. The worm's file is sent inside a ZIP archive attached to an infected message.

The worm has the following subjects hardcoded in its body:


referer.pif
004448554.pif
re.document.pif
new_document.pif
submited.pif
Screensaver.scr
movie.pif
Applications.pif
Application.pif
Your application
Re: Re: Document
Re: Re: Application ref. 003644
Re: Documents
Re: Screensaver
Re: Submited (Ref: 003746)
Re: Movies
Re: Movie
Re: Application

The worm has the following attachment names hardcoded in its body. The worm's executable file name that is sent in an archive is given in brackets:


Movie.zip (Movie.pif)
screensaver.zip (sky_world.scr)
document.zip (document.pif)
application.zip (application.pif)
your_details.zip (details.pif)

However, so far we only saw messages with the following characteristics:

Subject:

Re: Application

or
Re: Movie

Body:

Please see the attached zip file for details.

Attachment:

your_details.zip

The attachment contains the worm's file with DETAILS.PIF name. The fact that the worm uses only 2 subjects and 1 attachment name indicates that the randomizing routine of the worm has a bug.

Here's a screeshot of an infected message sent by the worm:


Posted Image

#8 User is offline   rik 

  • Veteran of the Psychic Wars
  • PipPipPip
  • Group: Members
  • Posts: 473
  • Joined: 16-May 03

Posted 02 July 2003 - 09:32 AM

It's a W32.SOBIG variant...probably W32.SOBIG.E@mm

http://securityresponse.symantec.com/avcen...sobig.e@mm.html

Symantec does have a removal tol you can download...

#9 User is offline   amdphr3@kXP 

  • /d3v/m$fn
  • PipPipPip
  • Group: Members
  • Posts: 462
  • Joined: 13-May 03

Posted 02 July 2003 - 10:02 AM

yup, i got the same thing from an address that was supposed to be from microsoft. Luckily i read an article on neworder.box.sk on it the day before so i knew what it was :) . I got AVG atm and it lets worms thru, it sux

#10 User is offline   C-Girl 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 458
  • Joined: 09-June 03

Posted 02 July 2003 - 11:18 AM

Palyh or something, right?

#11 User is offline   XPerties 

  • MSFN OG Senior
  • Group: Patrons
  • Posts: 2,994
  • Joined: 18-August 01
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 02 July 2003 - 11:31 AM

On emax hosting mail I get about 4-5 of these a day. I am not infected but I still get the zip files. Delete Delete, all day long.

#12 User is offline   Flash 

  • Flash has entered the building
  • PipPipPip
  • Group: Members
  • Posts: 482
  • Joined: 21-May 02

Posted 02 July 2003 - 01:10 PM

w00t, thanks guys and gals :) The virus gone :rolleyes: Used that removal tool... The worm actually expires soon i think anyway, so i heard, lol...

Thanks anyways.

#13 User is offline   C-Girl 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 458
  • Joined: 09-June 03

Posted 02 July 2003 - 01:11 PM

yeah, it doesnt expire, but it stops multiplying itself on the 15th of july

#14 User is offline   gamehead200 

  • SEARCH!!! SEARCH!!!
  • Group: Super Moderator
  • Posts: 7,036
  • Joined: 02-September 02
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 02 July 2003 - 02:17 PM

:) I get viruses in my e-mail everyday, but my virus scanner picks them up and deletes them...:D

I've gotten the SOBIG, the YAHA, the KLEZ, and the LOVELETTER viruses! :rolleyes: All deleted! :D

#15 User is offline   C-Girl 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 458
  • Joined: 09-June 03

Posted 02 July 2003 - 04:14 PM

ive got klez, yaha, bug bear, and palyh, the microsoft fake one. one was in a loveletter

'dear mary'
its john hre, hope you had great fun the other night on the beach strole...eh? lol

#16 User is offline   Unwonted 

  • Make me dinner, wench!
  • PipPip
  • Group: Members
  • Posts: 269
  • Joined: 21-June 03

Posted 02 July 2003 - 04:24 PM

Isn't sobig.e set to stop working on July 12th?

EDIT: Whoops! Just read flash's post. He mentionted it.

#17 User is offline   gamehead200 

  • SEARCH!!! SEARCH!!!
  • Group: Super Moderator
  • Posts: 7,036
  • Joined: 02-September 02
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 02 July 2003 - 04:42 PM

HandyBuddy, on Jul 2 2003, 06:24 PM, said:

Isn't sobig.e set to stop working on July 12th?

EDIT: Whoops!  Just read flash's post.  He mentionted it.

Why exactly would someone want to make a virus that stops spreading on July 12th? People can just advance their clocks...Can't they? :)

#18 User is offline   C-Girl 

  • Advanced Member
  • PipPipPip
  • Group: Members
  • Posts: 458
  • Joined: 09-June 03

Posted 03 July 2003 - 07:51 AM

but maybe thats what the virus makers expect...:) i got a free trail of something and had 23 days left set back my clock a week and when i went back to the trail it said it had expired :cry: lol

#19 User is offline   Doggie 

  • I'm very inactive :(
  • Group: Patrons
  • Posts: 2,676
  • Joined: 13-October 02

Posted 03 July 2003 - 08:31 AM

i've yet to get a viruse on my machine..
my parents got a one from the dr denmark or something lol.. and it stuffed there hdd

#20 User is offline   Flash 

  • Flash has entered the building
  • PipPipPip
  • Group: Members
  • Posts: 482
  • Joined: 21-May 02

Posted 03 July 2003 - 08:35 AM

Yeah, thats my first virus really, on this comp (had for over a year i spose).

On my old machine, thats another story, mostly hacks on that with my little hack wars, lol.

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

2 User(s) are reading this topic
0 members, 2 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2013 msfn.org
Privacy Policy