Fanatic Live: New Worm - Fanatic Live

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

New Worm .Pif worm propagates through msn Rate Topic: -----

#1 User is offline   keane

  • ...
  • Icon
  • Group: Project Leaders
  • Posts: 269
  • Joined: 02-January 03
  • Location:Canada

Posted 20 January 2005 - 02:43 AM

In the last 5 minutes I have recieved two file transfers from my trusted contacts, asking me to accept a .pif file, it seems that this is a new worm.

I haven't found anything on the net about this worm yet, but just don't accept these requests, and since I'm on my mac I can't dissect it more.

More to come..

Edit: Heh, I looked at it it's written in vb6... If any one more skilled than I at vb6 disassembly would like to take a look PM me.

This post has been edited by keane: 20 January 2005 - 03:02 AM

0

#2 User is offline   noroom

  • Because I Rock
  • Icon
  • Group: Valued Members
  • Posts: 3,477
  • Joined: 05-May 02
  • Location:Germany
  • Interests:Internet, Maths, Messenger, Programming, Music (Listening to and Playing), FileSharing, Computer / Software security... etc

Posted 20 January 2005 - 03:32 AM

any filenames? filesizes we should watch?

who sends .pif anyway, lol
0

#3 User is offline   keane

  • ...
  • Icon
  • Group: Project Leaders
  • Posts: 269
  • Joined: 02-January 03
  • Location:Canada

Posted 20 January 2005 - 03:44 AM

Filenames: Webcam_004.pif, sexy_bedroom.pif
Size: Both I have seen are 156kb

I have looked at it, what it does:

1. Sets your volume down all the way, so you don't hear the messages?
2. Copies itself to c:\windows\system32\lexplore.exe with readonly and hidden attributes.
3. Puts a key in the registry: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lexplore, so that it boots at runtime.
4. Locks up explorer. (disables right click and task manager)
5. Uses the windows messenger api to send file transfers to every online contact, every 5 seconds.

Oh yea, as for the .pif, it's basically a windows PE renamed to pif, I guess to trick people, it almost tricked me. I thought it was an image TBH.


I have made a program to remove it, PM me for it.

This post has been edited by keane: 15 February 2005 - 02:00 AM

0

#4 User is offline   Doggie

  • I'm Watching You -_-'
  • Icon
  • Group: Admins
  • Posts: 5,325
  • Joined: 04-February 02
  • Gender:Male
  • Location:Australia
  • Interests:Things that are interesting?

Posted 20 January 2005 - 09:52 AM

isnt new, its been around for a few months, funnily getting sent to people living in canada, the irony :lol:
0

#5 User is offline   Daniel

  • Liveâ„¢ n00b
  • Icon
  • Group: Admins
  • Posts: 4,598
  • Joined: 01-February 02
  • Location:New Zealand

Posted 20 January 2005 - 03:36 PM

Linked on Mess: http://www.f-secure..../bropia_a.shtml
0

#6 User is offline   keane

  • ...
  • Icon
  • Group: Project Leaders
  • Posts: 269
  • Joined: 02-January 03
  • Location:Canada

Posted 20 January 2005 - 09:18 PM

Heh, the f-secure descriptoin is just alittle nicer than mine ;)

Is it only being sent to canadians? doggie I'm confused.
0

#7 User is offline   Crack_X

  • V.I.P. Member
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 449
  • Joined: 07-June 03
  • Location:Dominican Republic
  • Interests:Girls , pc , music , guitar , chilling , etc.

Posted 20 January 2005 - 09:42 PM

I think he means that its spreading more in canada , havent seen that virus here in dominican republic yet
0

#8 User is offline   GaZ

  • Liveâ„¢ whore
  • Icon
  • Group: Admins
  • Posts: 1,153
  • Joined: 31-January 02
  • Location:England

Posted 20 January 2005 - 11:06 PM

doesnt supprise me it hasnt spread.. most people have contacts that live locally to them only some have over-seas contacts so the delay will be much longer... plus if its every 5secs people will be wary, as there have been other worms..
0

#9 User is offline   Jnrz

  • Supreme Refresh'r
  • PipPipPipPipPip
  • Group: Members
  • Posts: 296
  • Joined: 27-December 02

Post icon  Posted 22 January 2005 - 10:48 AM

vb6 ¿?
then it needs the vb6 run time libraries which I dont have :P
0

#10 User is offline   Doggie

  • I'm Watching You -_-'
  • Icon
  • Group: Admins
  • Posts: 5,325
  • Joined: 04-February 02
  • Gender:Male
  • Location:Australia
  • Interests:Things that are interesting?

Posted 22 January 2005 - 12:13 PM

then thats what you call a lame worm :P
0

#11 Guest_Paddy_*

  • Group: Guests

Posted 22 January 2005 - 06:39 PM

but if your from brazil, you can create as much malware as you want and still not be prosecuted... that stinks!

also chances are if you own up to creating a virus or worm, the antivirus labs wont believe you.. so you wont get prosecuted.

However if you do get caught, youre in for some serious sh*t... and if msn is as good as it says it is, it surely should have some sort of log of file transfers, and if they were really bothered *which im sure they are not* could find out who it originated from.

This post has been edited by Paddy: 22 January 2005 - 06:42 PM

0

#12 User is offline   Damian152

  • One post hero!
  • Pip
  • Group: Members
  • Posts: 1
  • Joined: 02-February 05

Posted 02 February 2005 - 10:04 PM

keane thank you for the program, but does it remove the registry logs too or just the worm?

I mean do i have to go back and delete any registry logs or something like that?
0

#13 User is offline   keane

  • ...
  • Icon
  • Group: Project Leaders
  • Posts: 269
  • Joined: 02-January 03
  • Location:Canada

Posted 15 February 2005 - 02:00 AM

Damian152, on Feb 2 2005, 05:04 PM, said:

...  does it remove the registry logs too?  ...
View Post


Yes.

This post has been edited by keane: 15 February 2005 - 02:01 AM

0

#14 User is offline   keane

  • ...
  • Icon
  • Group: Project Leaders
  • Posts: 269
  • Joined: 02-January 03
  • Location:Canada

Posted 15 February 2005 - 02:03 AM

Oh now it's mutated and is sending links.

The link I've recieved is: http://members.home....l/handcuffs.pif

Basic rule of thumb, don't run/download PIF files
0

#15 User is offline   noroom

  • Because I Rock
  • Icon
  • Group: Valued Members
  • Posts: 3,477
  • Joined: 05-May 02
  • Location:Germany
  • Interests:Internet, Maths, Messenger, Programming, Music (Listening to and Playing), FileSharing, Computer / Software security... etc

Posted 15 February 2005 - 02:11 AM

norton didn't pick that one out as a virus :o
0

#16 User is offline   Sev3r

  • One post hero!
  • Pip
  • Group: Members
  • Posts: 1
  • Joined: 15-February 05

Posted 15 February 2005 - 05:05 AM

ya just got that like 5 minutes ago. the handcuffs.pif one. wonderin if anyone knows how to remove it yet.
0

#17 User is offline   AMRMAX

  • One post hero!
  • Pip
  • Group: Members
  • Posts: 1
  • Joined: 07-March 05

Posted 07 March 2005 - 02:32 PM

I juz got it too. It started poping up www.searchmiracle.com popups. Please help us, Keane.
0

#18 User is offline   keane

  • ...
  • Icon
  • Group: Project Leaders
  • Posts: 269
  • Joined: 02-January 03
  • Location:Canada

Posted 12 March 2005 - 03:24 AM

As much as I'd love to help, I just can't right now.... really sorry to everyone, I'm just extremely busy with everything right now. In the mean time if you just want to get rid of the messages it sends to people just uninstall windows messenger.
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users