View Full Version : AOL Virus
rmcdaniels
06-15-2005, 02:38 PM
Got a AIM message from my boss with a link to a .pif file. It looks like most of my office clicked on it, and we are a technology company. It's really sad what a a bunch of noobs we are.
BlueFang08
06-15-2005, 02:40 PM
What did the virus do?
WTF is a .pif file extension (dos?)
rmcdaniels
06-15-2005, 02:51 PM
Yes, it's a DOS executable. I'm not sure what all it does, I didn't execute it, but it does open AIM and send itself to people on your list.
Weston-work
06-15-2005, 03:01 PM
A .pif file is back from the days before Windows 95... it's a program information file which tells Windows your preferences for running a non-windows based program. It's basically a shortcut to a program, but with some extra info added, and Windows sees it as an executable. The reason they used a .pif file here is either 1) they exploited some vulnerability in how windows handles those, or 2) they are using a seldom used executable file type to evade virus scanners.
sbiggi
06-15-2005, 03:01 PM
Yes, it's a DOS executable. I'm not sure what all it does, I didn't execute it, but it does open AIM and send itself to people on your list.
You got the Kelvir worm..... wipe and reload...
it loads a back door trojan and send shit out to IRC lists
I got this from that prelude guy in texas a couple of weeks ago. It wiped out my internet for like two weeks. Luckily my roommate fixed it for me. :)
smithz
06-15-2005, 04:26 PM
I got this from that prelude guy in texas a couple of weeks ago. It wiped out my internet for like two weeks. Luckily my roommate fixed it for me. :)
You have your own internet? I wish I had my own... :(
myshtern
06-15-2005, 05:08 PM
You have your own internet? I wish I had my own... :(
Yeah, AOL gives you a better internet.
You have your own internet? I wish I had my own... :(
Yeah, my dad was friends with Al Gore, he got me hooked up.
LeonZ
06-15-2005, 08:00 PM
Yea fucking STU was sending me that shit every 5 minutes few weeks ago, so I peed in his nose.
I have to deal with .pif files at work still :rofl:
Nothing like supporting 20 year old applications off Novell 4 server from early 1996.
I just got that sent to me but it's pretty damn easy to spot.... the message I got was...
"hahaha look at this! (link)"
Who say's that?? Seriously.... I never click those stupid things...
I can't even count the number of times i've gotten these... I always just tell the person and copy and paste what they just sent me... Most of the time they say "I didn't send you that" and than I can link them to the removal tool for the virus...
vBulletin® v3.7.1, Copyright ©2000-2008, Jelsoft Enterprises Ltd.