# This a virus?

**URL:** <https://boards.straightdope.com/t/this-a-virus/234101>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [March 13, 2004, 7:10pm UTC](https://boards.straightdope.com/t/this-a-virus/234101 "2004-03-13T19:10:12Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Silver\_Serpentine](https://avatars.discourse-cdn.com/v4/letter/s/3be4f8/32.png) [@Silver\_Serpentine](https://boards.straightdope.com/u/Silver_Serpentine)\
**Post date:** [March 13, 2004, 7:10pm UTC](https://boards.straightdope.com/t/this-a-virus/234101/1 "2004-03-13T19:10:12Z")

</div>

I got an Email yesterday that looks suspiscious. Didn’t open the attachement, of course. I can scan it with my mail program, but I don’t know how up to date it is.

I’ve never gotten a virus, so I don’t know what to look for.

* * *

From: [michaljoyner@aol.com](mailto:michaljoyner@aol.com)  
To: Me  
Subject: Re: Your product  
Date: Fri, 12 Mar 2004 17:49:00 -0800

Here is the file.  
Attachment

your\_product.pif  
.pif file

---

<div class="post-metadata">

**Author:** ![Lobsang](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lobsang/32/4067_2.png) [@Lobsang](https://boards.straightdope.com/u/Lobsang)\
**Post date:** [March 13, 2004, 7:25pm UTC](https://boards.straightdope.com/t/this-a-virus/234101/2 "2004-03-13T19:25:36Z")

</div>

It is highly likely to be a bad program. I don’t know how you define what makes something a virus, but I do know that that is not something you want to click on.

It looks very familiar as the type of trick e-mail virus writers like to use. delete it.

---

<div class="post-metadata">

**Author:** ![Lobsang](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lobsang/32/4067_2.png) [@Lobsang](https://boards.straightdope.com/u/Lobsang)\
**Post date:** [March 13, 2004, 7:27pm UTC](https://boards.straightdope.com/t/this-a-virus/234101/3 "2004-03-13T19:27:19Z")

</div>

Generally if you are suspicious of something you’ve recieved you are probably right to be suspicious of it. your ‘your product.pif’ is a perfect example.

---

<div class="post-metadata">

**Author:** ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)\
**Post date:** [March 13, 2004, 7:38pm UTC](https://boards.straightdope.com/t/this-a-virus/234101/4 "2004-03-13T19:38:36Z")

</div>

.PIF files are Program Information Files. These can only call DOS excutables, and can supply command-line parameters for them, as well as define some of the operating parameters. As such, it can only run a DOS-based executable that’s already on yoru system (e.q., FORMAT.EXE). You can open it for editing and see what the command line is. If you don’t feel comfortable doing so, go ahead and forward it to me, and I’ll see what’s in it.

---

<div class="post-metadata">

**Author:** ![Lobsang](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lobsang/32/4067_2.png) [@Lobsang](https://boards.straightdope.com/u/Lobsang)\
**Post date:** [March 13, 2004, 7:44pm UTC](https://boards.straightdope.com/t/this-a-virus/234101/5 "2004-03-13T19:44:13Z")

</div>

If I remember correctly PIFs were the shortcuts of early windows. and you could double-click them to run the program they call. wouldn’t that still happen? in other words if one called ‘format.exe’ wouldn’t it still be potentially unsafe?

---

<div class="post-metadata">

**Author:** ![GorillaMan](https://avatars.discourse-cdn.com/v4/letter/g/50afbb/32.png) [@GorillaMan](https://boards.straightdope.com/u/GorillaMan)\
**Post date:** [March 13, 2004, 7:52pm UTC](https://boards.straightdope.com/t/this-a-virus/234101/6 "2004-03-13T19:52:17Z")

</div>

SobigF, to take an example, spoofs any of the following attachment names:

> [@](#):
>
> your\_document.pif  
> document\_all.pif  
> thank\_you.pif  
> your\_details.pif  
> details.pif  
> document\_9446.pif  
> application.pif  
> wicked\_scr.scr  
> movie0045.pif

[http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM\_SOBIG.F](http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SOBIG.F)

---

<div class="post-metadata">

**Author:** ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)\
**Post date:** [March 13, 2004, 7:55pm UTC](https://boards.straightdope.com/t/this-a-virus/234101/7 "2004-03-13T19:55:40Z")

</div>

> [@Lobsang](#):
>
> If I remember correctly PIFs were the shortcuts of early windows. and you could double-click them to run the program they call. wouldn’t that still happen? in other words if one called ‘format.exe’ wouldn’t it still be potentially unsafe?

Very. In fact it could call FORMAT C: /U which would unconditionally format the drive.

---

<div class="post-metadata">

**Author:** ![Idlewild](https://avatars.discourse-cdn.com/v4/letter/i/8491ac/32.png) [@Idlewild](https://boards.straightdope.com/u/Idlewild)\
**Post date:** [March 13, 2004, 7:58pm UTC](https://boards.straightdope.com/t/this-a-virus/234101/8 "2004-03-13T19:58:58Z")

</div>

I think that’s netsky… you can check at [symantec.com](http://symantec.com), searching on the subject line of the email or the name of the attachment and it’ll tell you if it’s a known virus. I say I think it’s netsky because I had that come through (and get fielded by my virus filter) this week and it looks the same.

---

<div class="post-metadata">

**Author:** ![Silver\_Serpentine](https://avatars.discourse-cdn.com/v4/letter/s/3be4f8/32.png) [@Silver\_Serpentine](https://boards.straightdope.com/u/Silver_Serpentine)\
**Post date:** [March 14, 2004, 2:33am UTC](https://boards.straightdope.com/t/this-a-virus/234101/9 "2004-03-14T02:33:27Z")

</div>

**Q.E.D.** - I’m a`sending it your way.

---

<div class="post-metadata">

**Author:** ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)\
**Post date:** [March 14, 2004, 5:24am UTC](https://boards.straightdope.com/t/this-a-virus/234101/10 "2004-03-14T05:24:21Z")

</div>

> [@Silver Serpentine](#):
>
> **Q.E.D.** - I’m a`sending it your way.

No mail yet.

---

<div class="post-metadata">

**Author:** ![Mad\_Matt](https://avatars.discourse-cdn.com/v4/letter/m/a3d4f5/32.png) [@Mad\_Matt](https://boards.straightdope.com/u/Mad_Matt)\
**Post date:** [March 14, 2004, 9:08am UTC](https://boards.straightdope.com/t/this-a-virus/234101/11 "2004-03-14T09:08:51Z")

</div>

There is a virus called Netsky.d doing the rounds at the moment. More information can be found at the Symantec [Netsky.d](http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky.d@mm.html) web page. I’ve had a quick look at the site. The subject and attachment name on your message look like they could be Netsky.d or a variant. **Q.E.D.** may be able to confirm this when he gets a copy of your message.

I’m sick of Netsky - my virus checker has detected about 12 inbound copies of this virus in the last week.

---

<div class="post-metadata">

**Author:** ![Mad\_Matt](https://avatars.discourse-cdn.com/v4/letter/m/a3d4f5/32.png) [@Mad\_Matt](https://boards.straightdope.com/u/Mad_Matt)\
**Post date:** [March 14, 2004, 9:13am UTC](https://boards.straightdope.com/t/this-a-virus/234101/12 "2004-03-14T09:13:26Z")

</div>

**Idlewild** how did I not see your post? You said everything I said only 13 hours earlier. Must drink more coffee to wake up. I suppose I tried to pin it down and provided a link… Yeah, that’s it. 🙂

---

<div class="post-metadata">

**Author:** ![Silver\_Serpentine](https://avatars.discourse-cdn.com/v4/letter/s/3be4f8/32.png) [@Silver\_Serpentine](https://boards.straightdope.com/u/Silver_Serpentine)\
**Post date:** [March 14, 2004, 9:30pm UTC](https://boards.straightdope.com/t/this-a-virus/234101/13 "2004-03-14T21:30:49Z")

</div>

**Q.E.D.** - Huh, I sent it to the Email in your profile. Is it different now?

Sending again.
