WARNING: New badtrans variant

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

whateverdude

Senior member
Oct 6, 2000
514
0
0
I got one yesterday too with the attachment "fun.mp3.pif" outlook wouldnt preview or let me open it. I just deleted it, is that ok? I dont have AV software :eek:
 

Hossenfeffer

Diamond Member
Jul 16, 2000
7,462
1
0


<< I got one yesterday too with the attachment "fun.mp3.pif" outlook wouldnt preview or let me open it.
I just deleted it, is that ok? I dont have AV software :eek:
>>



I'd definitely recommend picking up an AV program. For now, check the registry for
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows \CurrentVersion\RunOnce\Kernel32=kernel32.exe
The worm might have executed automatically.
 

whateverdude

Senior member
Oct 6, 2000
514
0
0
I havent had AV software for about 3 years. flawed logic I know, but ive just relied on my instincts to steer clear of suspicious email.

thanks for the tip!
 

AntaresVI

Platinum Member
May 10, 2001
2,152
0
0
I got it too. Bad stuff - My stupid ISP shut down my email account! Dont forget that it infects kdll.dll too, according to my norton (that i had uninstalled 4 nights ago...ARGH!)
 

MaxDSP

Lifer
May 15, 2001
10,056
0
71
In case someone is still having problems, this is how I got rid of the virus:

-Ran the Free HouseCall virus scan linked above
-AV scan detected 2 infected files, kernel32.exe and kdll.dll in the C:/WINNT/system32 folder in Win2K Pro
-CTRL+ALT+DEL to open Task Manager, the end kernel32.exe process from Processes tab
-Go back to system32 folder and you will now be able to delete the 2 files, if you weren't able to before
-Reboot and rescan system

Hmmmm, just checked Hotmail account and deleted another infected e-mail. This thing's gettin crazy. :Q
 

MWink

Diamond Member
Oct 9, 1999
3,642
1
76
YIKES!!! I just got an infected Email from my English teacher. Of course I didn't open it. When I tried to save it to the HD (I already knew it was a virus) my virus scanner caught it right away. The bad part is I'm sure it got sent to everyone on the listserv (aka all his English classes). I'm sure most of them will not realize what it is. I sent him an email about it right away. This has to be at least the second virus he has been infected with this semester.
 

Burnt

Platinum Member
Mar 20, 2001
2,211
0
0
YOU_are_FAT!.TXT.pif

heh...nice attachment name. Good ole norton will protect me
 

Hossenfeffer

Diamond Member
Jul 16, 2000
7,462
1
0


<< Why do you open attatchments from random junkmailers in the first place? :) >>



This worm can run automatically on a large percentage of users' machines. This is one of the primary reasons it's been upgraded to such a risk level. By all means, get the word out.

And somebody get that damn English teacher some anti-virus software ;)
 

kyutip

Golden Member
Jul 24, 2000
1,729
0
0
Is there any way to set up Outlook Express to reject any mail with attachment that have extension .scr or .pif ?
 

MajesticMoose

Diamond Member
Nov 14, 2000
3,030
0
0
my english prof sent it to me (same prof as MWink). Guess that means i should ignore all of his mail:)

m00se

edit: i opened the thing in outlook(actually it did automatically when i was selecting it for deletion, but no infection:)


 

MaxDSP

Lifer
May 15, 2001
10,056
0
71


<< Is there any way to set up Outlook Express to reject any mail with attachment that have extension .scr or .pif ? >>



I tried to figure it out but haven't had too much luck. Temporarily, I've set Express to only download the Hotmail e-mail headers for all 3 of my Hotmail accounts so it only downloads the message and the attachment if I want it to after I deem it to be virus-free.

If someone finds a permanent fix for this flaw, please post itor PM me. Thanks
 

jkersenbr

Golden Member
Jun 22, 2000
1,691
0
0
Just downloaded a variation of this as stuff.MP3.pif from someone I don't know. Appears to be the newest variant. Info Link.

Fortunately, I don't use the preview pane. I was curious what the message was, so I opened the message and clicked cancel on the "save or open" dialog box so I could see the filename.

My registry is clean.

I've been using the net since 1996 and have never been infected by a virus. And I have never ran resource hogging anti-virus software which isn't updated fast enough to catch the fast-moving threats.

If you do these, you won't get a virus:

1) Don't open any executable attachments.
2) Don't open any attachments you aren't expecting.
3) Don't use the stupid preview pane.
4) Don't let other people fool with your system (they can plant trojans if you are too smart to download them)
 

weezergirl

Diamond Member
May 24, 2000
3,366
1
0
i got an e-mail like this. it came with a text file and a pif file. i opened up the txt. file...but i didn't open up the pif file. i just deleted the whole e-mail after looking at the txt. file. i was using outlook express. does anyone know if the txt file is bad to open too??
 

yllus

Elite Member & Lifer
Aug 20, 2000
20,577
432
126


<< i got an e-mail like this. it came with a text file and a pif file. i opened up the txt. file...but i didn't open up the pif file. i just deleted the whole e-mail after looking at the txt. file. i was using outlook express. does anyone know if the txt file is bad to open too?? >>


Unfortunately you're probably infected now, weezer. When you're prompted to open a file called, for example, "Humor.TXT" it's probably actually named "Humor.TXT.pif" and contains the virus code, Windows just fails to report the second extension (.pif). Run a scan ASAP, might want to disconnect physically from the Net in the meantime.
 

weezergirl

Diamond Member
May 24, 2000
3,366
1
0
actually i ran that online scanning thing....it detected no viruses. is that ok? the txt file had 0bytes...