PDA

View Full Version : Advance warning for people using MSN:Messenger!



Ascension
26-01-05, 20:42
There is a new virus floating round, know I know most people here are virus wise.. but for those who arnt, dont accept anything suspicious or that ends in
.pif

Ive had these sent me by 4 people now.. just because they accepted the virus download!

you wont know about the infection it it sends filre transfer requests to all your contacts! without you knowing.

QuantumDelta
26-01-05, 20:57
MSN were supposed to have shut this kinda virii down, but blah.

ty for the heads up anyway

landofcake
26-01-05, 21:19
Cheers Ascention, i'll get the word out to the computer illiterate on my MSN list (90% of the list i guess ...)

:angel:

Lachlan
26-01-05, 21:34
Cheers Ascention, i'll get the word out to the computer illiterate on my MSN list (90% of the list i guess ...)

:angel:
Send them a file transfer request with a document explaining why they shouldn't accept file transfers.

Lexxuk
26-01-05, 23:24
.pif iirc is a shortcut file, so whats the shortcut too? O_o

Ascension
27-01-05, 00:07
.pif iirc is a shortcut file, so whats the shortcut too? O_o
all the virus associated items are shortcuts.. im only guessing to an external source.. which then d/l's something!

Lexxuk
27-01-05, 00:08
/me strokes my firewall, both of em, and my dmz :D

i'm a security nut, anythin says "lemme access internet" i say "hell no!" then think "oh, err, ok"

Tratos
27-01-05, 00:21
thought it was curious that somone who i hadnt talked to online for a few months was sending me a file, luckily i thought wtf O_o and declined, at least i know what it was going to be now, cheers much.

Ascension
27-01-05, 01:26
thought it was curious that somone who i hadnt talked to online for a few months was sending me a file, luckily i thought wtf O_o and declined, at least i know what it was going to be now, cheers much.

Wo0t.. Ascy saves the day :D

Dribble Joy
27-01-05, 01:35
MSN crashes my house's router when I try to receive a file anyway, so meh.

Lexxuk
27-01-05, 01:36
MSN crashes my house's router when I try to receive a file anyway, so meh.

thats coz MSN is evil, and you need to set your router up to use it correctly, i just flashed another routers firmware onto mine for uPnP :D

Morpheous
27-01-05, 09:24
my Top tips:

1. Don't use MSN, use ICQ or something.
2. Tell MSN to automatically scan all d/led files.
3. Don't run MSN on your main PC if you must use it.

I've never used MSN in over 6 years, and it's not coming back on. This virus is just one example of why. Because it's poorly maintained, maybe?o_O

Edit: uPnP is one of the largest security flaws in Windows.... so if you've enabled it, turn it off now!
http://www.grc.com/unpnp/unpnp.htm
Also, you might wanna run ShieldsUp! (At same site) to check your firewall...

Easiest solution is just to stop using MSN. I'm mainly using Skype atm, free internet chat and internet telephony... very nice app. www.skype.com. And you can get credit to call landlines :D

Obsidian X
27-01-05, 10:24
Edit: Delete plz, I seem to have posted 3 posts somehow :(

Obsidian X
27-01-05, 10:25
deleted

Obsidian X
27-01-05, 10:26
.pif iirc is a shortcut file, so whats the shortcut too? O_o

.PIF files are MS-DOS shortcuts, yet executables in their own right. I'm not exactly sure why, but rename any executable to .PIF and run it, it works exactly the same as when it had an EXE extension.

EDIT: There was a worm going round MSN like this about 2-3 years ago, and it wouldn't suprise me if its the same one :rolleyes:

Xeno LARD
27-01-05, 14:35
My MSN doesn't even sign in atm :S.

Jesterthegreat
27-01-05, 14:37
is it that hard not to open / download things you dont know?

its the same as with email attatchments...

Lexxuk
27-01-05, 14:40
my Top tips:

1. Don't use MSN, use ICQ or something.
2. Tell MSN to automatically scan all d/led files.
3. Don't run MSN on your main PC if you must use it.

I've never used MSN in over 6 years, and it's not coming back on. This virus is just one example of why. Because it's poorly maintained, maybe?o_O

Edit: uPnP is one of the largest security flaws in Windows.... so if you've enabled it, turn it off now!
http://www.grc.com/unpnp/unpnp.htm
Also, you might wanna run ShieldsUp! (At same site) to check your firewall...

Easiest solution is just to stop using MSN. I'm mainly using Skype atm, free internet chat and internet telephony... very nice app. www.skype.com. And you can get credit to call landlines :D

I stopped using ICQ about 4-5 years ago, its got more security flaws than MI5 HQ :p

uPnP *can* be unsafe depending on how you look at it, grc's report is based on when uPnP first came out, which is quite a while ago and the specifications have changed quite a lot and is naturally updated in Windows and turned off by default, even with uPnP aware hardware.

My router itself provides the uPnP however, Windows never touches it, the firewall on my router protects the uPnP activity, opens and closes ports as requested by MSN, which is a bit more secure than having to open ports on my router to allow file transfer for instance.

nobby
07-02-05, 18:47
My mate sent me a file "Nude_women"
when i asked about it, she had no clue about it!

nobby
07-02-05, 18:49
Oh well.
I think i know the guy's address who made it.

steve.Yusan@gmail.com
He changed my contact email address on Amazon and spent 85 quid...
BUGGER!

Oh well, i'd like a wee reward for catching the bloke!

jernau
07-02-05, 19:09
my Top tips:

1. Don't use MSN, use ICQ or something.
ICQ is a festering pile of ugly, resource-munching crap. I wouldn't wish it on my second-worst enemy.

wrt uPnP - Much as it pains me to agree with anything that ass-clown Steve Gibson says, I agree. The spec for it may as well start "you're too stupid to own a PC so we're going to make sure yours get boned by 5 year olds".

Skype is indeed pretty neat though it's non-standardisation will kill it in the near future I expect. I wouldn't use it as a text-chat system though.



@DJ - that's just weird, update the router BIOS.

Maui
10-02-05, 16:40
damn man, why did u make this topic, anyone stupid enough to accept random files, whould not be allowed on the net ! aka let em get a virus and suffer pc breakage :P

Morganth
10-02-05, 16:46
Good thing my router does what its told. I can get infected by any virus/trojan and my router won't allow the connection to go through if I haven't allowed the target port to be open.

<= Likes being computer literate

Apart from anything, my computer has 3 AV proggies running at once, which go mad whenever a virus/trojan gets even near my PC.

Maui
10-02-05, 16:50
look m8, never have more then 1 av program runnin, its common knowlage that having more then 1 fightin over a virus totaly messes up your system.

also, yo pc must be hella slow with 3 av thingies runnin constantly O_O

jernau
10-02-05, 16:52
<= Likes being computer literate

.....

Apart from anything, my computer has 3 AV proggies running at once, which go mad whenever a virus/trojan gets even near my PC.
Sorry to have to say it but those two statements are mutually exclusive.

Three AV programs is just stupid, all you'll do is kill performance for no gain. Get one that works.

Maui
10-02-05, 17:35
Sorry to have to say it but those two statements are mutually exclusive.

Three AV programs is just stupid, all you'll do is kill performance for no gain. Get one that works.


I really didnt want to hurt his feelings, so im kinda glad u did it for me :P

jernau
10-02-05, 17:44
I really didnt want to hurt his feelings, so im kinda glad u did it for me :P
I tried not to :(.


I have a truly useless AS400 contractor here today so I'm probably not at my most tolerant.

-Demon-
11-02-05, 00:41
Moved off ICQ a logn time ago...went crap around about the time AOL brought it out and tried scamming ppl.

Well AOL says it all really!

hehe

MkVenner
11-02-05, 00:47
yeah i tried ICQ, but no one could ever reach me on it...just use MSN, AIM and Skype pretty much...

-Demon-
11-02-05, 00:58
Don't get me wrong it was a great IM proggie and really the first one to make it popular, I was using it back in '97 and I think it was quite new then.

Good program turned into a advert whore proggie and bloated with too many features that made it less usable and features it didn't truely need.

nobby
13-02-05, 03:03
Moved off ICQ a logn time ago...went crap around about the time AOL brought it out and tried scamming ppl.

Well AOL says it all really!

hehe


how did they scam?

Morganth
13-02-05, 03:11
For all those whininh about my AV setup, go screw yourselves.

I have NO performance loss at all, as I have run stress tests on my system with programs running and all process except critical processes running from memory. I never get a virus/trojan, so my 3 AVs don't fight at all over them.

There is no such thing as too much security.

And I bet all you whiners have a firewall running I guess? Thats not hardware or self coded?

nobby
13-02-05, 03:12
just be a man and ignore the bullies :)

Morganth
13-02-05, 03:16
just be a man and ignore the bullies :)

I just wanna know if they use a firewall, then we will see who knows what.

trigger hurt
13-02-05, 03:34
I run smoothwall on my *nix box, does that count?

Morganth
13-02-05, 03:38
I run smoothwall on my *nix box, does that count?

*nix > all

So yes, it does.

And I am also pretty sure you know what you are talking about trig :p

Xeno LARD
13-02-05, 04:08
I have my own iptables rules list on my *nix box, that is the webserver + router (security flaw right there, heh).

jernau
13-02-05, 12:54
how did they scam?
Selling personal details.
Refusing to cancel accounts.
Overcharging.

Take your pick, they've done them all over the years.



@Morganth - Believe what you want but you are losing performance. If you aren't then they aren't doing anything in which case why have them there.

It's your PC so do what you want with it but don't expect others not to comment if you publicly declare that you do something daft.

Morganth
13-02-05, 18:32
@Morganth - Believe what you want but you are losing performance. If you aren't then they aren't doing anything in which case why have them there.

It's your PC so do what you want with it but don't expect others not to comment if you publicly declare that you do something daft.

Either way I bet my PC > yours.

jernau
13-02-05, 19:42
Either way I bet my PC > yours.
Sorry dude, I left the playground behind me decades ago. Find someone else to play that game.

Morpheous
13-02-05, 23:33
My internet connection -> Smoothwall (FC3, SElinux) -> Cisco firewall -> Internal LAN Firewall, Netgear -> Software firewall (Sygate) -> My PC

^_^

And you can have too much security. 3 Virus scanners can conflict, screw things up and diagnose their ID libraries as viruses, killing each other. Been there, done that, reformatted and put Fedora 3 on.

r3yka
22-02-05, 02:57
meh i already got the virus from my stupid sister..doesn't seem to be doing much atm...jus sending itself to everyone i kno

Ascension
22-02-05, 09:07
meh i already got the virus from my stupid sister..doesn't seem to be doing much atm...jus sending itself to everyone i kno
watch ya isp dont cut you off for for exteme bandwidth usuage ;)

dark_reaper
25-02-05, 03:26
meh i already got the virus from my stupid sister..doesn't seem to be doing much atm...jus sending itself to everyone i kno

A very good reason not to use IM's.
I dont even let my sister or my parents use my computer. They have to go through a key, and a password.

Some time I wish they make a PC for computer illeterates, and trash the Mac computers.

imAchair
25-02-05, 10:15
ohhh i gotta unblock some ppl now :lol: isnt the file names like "she can fit all of it in a teapot.pif" or some crap like that?

naimex
25-02-05, 10:20
ohhh i gotta unblock some ppl now :lol: isnt the file names like "she can fit all of it in a teapot.pif" or some crap like that?

and webcam.pif

hot sexy nude gurl.pif

and such yes.

i noticed the funny.exe thing is still being sent.. thought it was gone long time ago :confused: must be having a 1 year in circulation anniversary soon. :rolleyes:

Dribble Joy
07-03-05, 04:26
I've got this stupid little fucker on my machine now, curtousy of my little sister.
Norton doesn't know it's there, and neither does the free scan that msn gives you :p.
A search for .pif finds two of them, neither with file names that look iffy. So dunno if they are legit msdos apps or what. Nor are they in a place I would expect (root windows folder and the winzip folder).

While we are at it, I have a file. Which I.... aquired, and in good old tradition, it isn't what it was meant to be.
I can't see that it's doing anything. It's clean according to norton and my adware progs, it won't delete (being used by windows apparently :rolleyes:) and I can't see it under processes.
How can I get rid of it?

MkVenner
07-03-05, 04:37
i almost got it from crazy lol

it looks just like a normal message

"omg this is funny! http://jose.rivera4.home.att.nt/cute.pif"

mishkin
07-03-05, 14:39
Ah, this little buggar is kinda fun, I got it sent to me by an old clan-mate, ran it... and 2 minutes later I got the message "omg this is funny! http://jose.rivera4.home.att.nt/cute.pif" from 4 of the people on my contacts-list :D

It's so goddamn hilarious :lol: :lol: :lol:

Anyway, getting rid of it is pretty simple, it's just a matter of killing the process and then removing it from all startup-lists...

http://truedeath.com/2005/02/16/removing-the-msn-virus/

Happy Hunting! ;)

//edit - DJ, what kind of file?
///Edit - Oh, and while talking about security, I have no firewall whatsoever (I would have if my adsl-router wouldn't cut me off every 20 minutes if I enable NAT), so the only protection I have is this german anti-vir, which is very good tbh... get it at http://www.anti-vir.de/ (they have an english site too, but that one's almost always inaccessible due to it being overloaded...)
Free updates and everything + it takes up MUCH less resources than any other av I know of... ;)

Dribble Joy
07-03-05, 15:27
It's a 400mb exe file, presumably an installer, but it doesn't work, and is apparently in use.

I have also found the cause of some of the popups I have been getting. Little .exe files in c:\, that won't let me delete them.