Filenames: Webcam_004.pif, sexy_bedroom.pif
Size: Both I have seen are 156kb
I have looked at it, what it does:
1. Sets your volume down all the way, so you don't hear the messages?
2. Copies itself to c:\windows\system32\lexplore.exe with readonly and hidden attributes.
3. Puts a key in the registry: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lexplore, so that it boots at runtime.
4. Locks up explorer. (disables right click and task manager)
5. Uses the windows messenger api to send file transfers to every online contact, every 5 seconds.
Oh yea, as for the .pif, it's basically a windows PE renamed to pif, I guess to trick people, it almost tricked me. I thought it was an image TBH.
I have made a program to remove it, PM me for it.
This post has been edited by keane: 15 February 2005 - 02:00 AM