Forum Moderators: phranque

Message Too Old, No Replies

.pif files in e-mail may be carrying virus/worm

Have been arriving with simply RE: in the title

         

click watcher

1:56 pm on Nov 26, 2001 (gmt 0)



so far today i've recieved 3 blank emails with .pif attatchments,

i haven't opened any, am wondering if its some kind of virus.

anyone know??

i thought pif files were some kind of virtual business cards, but it would be most unusual to get 3 sent in one morning all with no covering email

agerhart

2:18 pm on Nov 26, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I received one today that has the title - "Spreadsheet on Search Engine Stats at Web Master World"

I have no idea where this came from, and it is trying to open this .pif file.

engine

2:24 pm on Nov 26, 2001 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Click_watcher, pif files (program information file) are windows/program-specific files. Usually, they are setup files to enable a program to run effectively by allocating memory and resources specific to that program when run.

If I remember correctly, the pif files used to help DOS programs run in windows 3.1, although, it seems, they are still used.

I have no idea why someone would send you this without content, however, I would beware of the content, and, also, beware of the e-mail.

angiolo

2:38 pm on Nov 26, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Be careful!

I received several files with a .pif extension or doc.pif extension: They had the Syrcam virus.

There was a bug in Macafee antivirus that didn't intercept the email containing the attachement file with that extension. double extension as:
doc.pif or
exe.pif

I was suspicios and I manually did a scansion: there was a Syrcam virus!! If you are using Macafee you should add the PIF extension in the optional extensions, no matter if you selected scan all files.

click watcher

3:03 pm on Nov 26, 2001 (gmt 0)



phew!!! thanks guys.

i investigated further and quickly updated my norton antivirus,

they all had a nice little virus...

for reference two had the attatchment doc.doc.pif

Napoleon

3:39 pm on Nov 26, 2001 (gmt 0)



Odds on it's a virus... I have had a VERY hard day with it.

The W32.Badtrans.B@mm virus got through this morning on a blank email with a pif attachment. It zipped through my address book like nobody's business. I eventually cleaned it up... eventually.

The thing about it was that I didn't open it (not being totally stupid). The fact that it was visible unopened through the window of my Outlook Express box was enough. I think it opened itself by virtue of a foreign character in the window which tried to download the translater font. Off it went.

If you get a blank message with an attachment therefore... don't even highlight. Grab and delete.

Thanks again M$ for your great security.

click watcher

3:46 pm on Nov 26, 2001 (gmt 0)



sorry to hear that napoleon

>>>The W32.Badtrans.B@mm virus got through this morning

thats what was transported to me too.

all the best.

FreeBee

10:25 pm on Nov 26, 2001 (gmt 0)

10+ Year Member



card.DOC.pif; info.DOC.scr; news_doc.DOC.scr etc. = W32.Badtrans.B@mm [symantec.com]

Arrived without any attachment indicator in Outlook! The attachment only became evident on preview or attempting to open the message with a request to save attachment to disk.

engine

8:57 am on Nov 27, 2001 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Seems like this one is going to run and run. Got two of the blighters in the inbox this morning.

Thanks to wmw members for bringing this to our attention.

Eric_Jarvis

12:33 pm on Nov 27, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



thanks from me too...all workstations here now configured to scan .pif files

:)

horoscopes2000

9:12 pm on Nov 27, 2001 (gmt 0)



I have noticed an increase in the amount of these received this week. Also, .scc files, which I delete immediately (or is that .ssc, I can't remember).

Also an increase in Sircam32 long after I thought it had died out.

agerhart

9:14 pm on Nov 27, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I had never received any of them before this week. I think I have received at least 10 already.

horoscopes2000

9:33 pm on Nov 27, 2001 (gmt 0)



Those extensions I mentioned to look out for are .scr

I have received another 3 between posting my original message, and this one.

mivox

9:37 pm on Nov 27, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I've received a few .pif files with my email, but they don't actually show up in my inbox... Not that it would be a threat to my system anyway. Mac is good. :)

heini

9:45 pm on Nov 27, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



>not that it would be a threat to my system

Itīs only(?) a threat to systems using MS outlook. Why are so many people still using it?

horoscopes2000

10:20 pm on Nov 27, 2001 (gmt 0)



I *think* MS released patches to prevent the autoexecution of attachments. The question is, why are some people still using it *unpatched*?

mivox

10:26 pm on Nov 27, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I can't imagine installing an Outlook patch is much easier than installing Eudora (if there is an Outlook patch)... and you don't need to worry about patching Eudora in the future. People continue using Outlook for the same reason they don't install security patches, I think: Default Configuration Syndrome.

My boss has a nice little NT network here, and a very elaborate network security policy for everyone to follow... but he didn't know it was possible to change the default browser text size, and never considered using a non-MS email program (which would pretty well eliminate the security issues he's worried about).

A lot of people are only as computer literate as they absolutely need to be... there's no curiosity to go beyond the basics, and patching (or installing) software isn't really basic. We have our network support contractor come in to do all Windows software installations... my lonely little Mac is the only machine that's taken care of in-house, and only because I happen to know how.

Key_Master

11:10 pm on Nov 27, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I just recieved 8 of them within the last couple of hours. Every one of them different. This doesn't include the dozen or so I've already recieved today.

Just got another one...

mayor

2:36 am on Nov 28, 2001 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I've been getting hit by this badtrans variant b virus too.

More details at:

symantec [symantec.com]

and:

nai.com [vil.nai.com]

About patching so it doesn't automatically execute:

ms.com [microsoft.com]

Unfortunately, I haven't found a way to filter it from my e-mail yet.