Novahq.net Forum

Novahq.net Forum (https://novahq.net/forum/index.php)
-   Tech Support (https://novahq.net/forum/forumdisplay.php?f=37)
-   -   email virus? (https://novahq.net/forum/showthread.php?t=1548)

Steve 03-10-2002 02:25 PM

email virus?
 
anyone else had this email?

from: NIKHIL

Hi! How are you?

I send you this file in order to have your advice

See you later. Thanks

attachment: Book1.xls.pif [202 Kb]


i must of had it at least 10 times in the last year. i'm pretty sure its a virus email, but does anyone know what the virus is called? i'd download it and find out but it might do something bad like infect my boot sector:mad: :mad:

Necromancer 03-14-2002 12:27 AM

I think it's a worm, called Bookworm, but I could be wrong. I've seen that e-mail before twice, too.

Muninn 04-09-2002 10:43 PM

Well i got one from someone on earthlink it was a WORM sircam32, and it said here is the information you requested.
and as the attachment it had a program i made as the attachment but it was really the SIRCAM32 Worm but i did not open it...so...yeah...

zza1pqx 04-14-2002 06:36 PM

I don't know a huge amount about programing but how would a PIF file be able to infect a PC and do anything?
I remember PIF files from the good old days of DOS.
I have no idea why anyone would want to send someone one so I would be like you SB and suspiscious.
However, I just can't think what even a malicious PIF could actually do. Any ideas?

Necromancer 04-17-2002 10:43 PM

The virus itself is not a PIF file. The programmer obviously wanted to make the file look like one, but he made the mistake of putting a second extension onto the file. This is a characteristic trademark of a virus if it's downloadable. Otherwise, the only other files that have double extensions are Internet files. THis would make the virus easier to circulate on the Internet.

For the sake of this lecture, let's make an example out of "Book1.xls.pif". Now, the way a PIF file could infect a PC is such that the PIF contains data that would define a program hidden in the XLS part of the file. This would effectively turn the file into an internal duplicate, or a file within a file. And yes, this is possible. I've done it with C++. It makes a BIG mess of the file, but when you put a PIF into the mess, you get calculated instructions as to how the file operates. So, as the file is being read, it can also be running a background program at the same time designed to fubar your computer. That's why it's easy to identify viruses as a file having double extensions that have no business being on the Internet, such as XLS and PIF.

Moral of the Story: Don't download a file that has double extensions! Especially ones like "filename.jpg.gif"! Any file which has two extensions from picture files, like "filename.jpg.gif", is definitely a virus, unless someone forced a double extension in their file system, which is highly unlikely.

Hope I have been helpful.

zza1pqx 04-30-2002 08:53 PM

Yes. Of course that is exactly how a PIF file could be used.
Once again it is proven how stoopid I am.
Cheers Nec.

Necromancer 05-25-2002 09:21 PM

No prob. I've had some fun experimenting with virus files with my C++ program, and the things people throw into them can be very strange indeed.

cR4zY 06-19-2002 07:24 AM

i got an email:

Sender: Star
Subject: i made something funny (not virus)
Attachment: worms.zip



:rolleyes: didnt know the guy :rolleyes:

Steve 06-19-2002 07:29 AM

hehe
the fact that he put ( not a virus ) makes it extremely dodgy lol


im stil getting virul emails everyday now. one of the latest viruses that has a large file attached - about 100 - 200k but there is no message or attachment visible. someone or some ppl still have it in their inbox and i just cant believe they have it after months and months. some ppl need to sort their stuff out

Scott 06-19-2002 10:56 AM

I got them stupid things too. that's why I changed my email.

DevilDog#1 07-13-2002 02:51 AM

Will you people stop d/l porn! hehehehe


All times are GMT -5. The time now is 04:13 PM.

Powered by vBulletin®