LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 01-22-2004, 04:48 PM   #1
r_jensen11
Senior Member
 
Registered: Apr 2003
Location: Minnesota, USA
Distribution: Slack 10.0 w/2.4.26
Posts: 1,032

Rep: Reputation: 45
Question Opening Windows viri in Linux...


I was just looking through my bulk-mail folder, and I saw a single message with an attachment. I thought it was odd, so I looked at the subject, which read: "Hi"

Now this struck a cord with what I had just read, no more than 2 days ago, probably, about a new virus spreading around like mad. So I opened it up, and here's the text of the message:

Quote:
Test =)
rnoktajcmktgwodee
--
Test, yep.
If this isn't the Bagel virus, I don't know what is. Anyway, there's an attachment left in the message, which I havn't opened yet. I was wondering, is there any way I could open this sucker up in Linux, see what makes it tick, etc? It'd be interesting, from an educational standpoint, as to why firewalls and virus-checkers don't pick these things up all the time.
 
Old 01-22-2004, 04:56 PM   #2
neilcpp
Member
 
Registered: Jul 2003
Location: England
Distribution: Debian Jessie, FreeBSD 10.1 anything *nix to get my fix
Posts: 329

Rep: Reputation: Disabled
I would save it to a floppy. Mount the floppy & then view the file / attachment with a viewer... but i dont know how sophisicated viri are now!!
 
Old 01-22-2004, 05:30 PM   #3
tricky_linux
Member
 
Registered: Jul 2003
Distribution: Red Hat Linux 9.0; Old and Solid
Posts: 674

Rep: Reputation: 30
could you send me a copy of that virus at hotmail.
i will appreciate for it.
i want to look it up myself.

Last edited by tricky_linux; 01-23-2004 at 12:42 PM.
 
Old 01-22-2004, 05:38 PM   #4
r_jensen11
Senior Member
 
Registered: Apr 2003
Location: Minnesota, USA
Distribution: Slack 10.0 w/2.4.26
Posts: 1,032

Original Poster
Rep: Reputation: 45
Sent. However, I don't know if the attachment got forwarded. I'd be very careful about posting your email address like that. I would've done something like linux886 <at> hotmail <dot> com or something along those lines. If the attachment didn't get forwarded, I'll send it from my Linux box.

I would attach the file here, but I'm afraid of the repercussions.
 
Old 01-22-2004, 05:49 PM   #5
h/w
Senior Member
 
Registered: Mar 2003
Location: New York, NY
Distribution: Debian Testing
Posts: 1,286

Rep: Reputation: 46
what file xtn is it?
 
Old 01-22-2004, 06:58 PM   #6
r_jensen11
Senior Member
 
Registered: Apr 2003
Location: Minnesota, USA
Distribution: Slack 10.0 w/2.4.26
Posts: 1,032

Original Poster
Rep: Reputation: 45
If you guys want the email, I'll send it to you. But you have to email me first. Plus, you have to promise HERE that you won't do anything malicious with it. I don't want the FCC or anyone pounding on my door anytime soon.

My email: r_jensen11 <at> yahoo <dot> com
 
Old 01-22-2004, 07:08 PM   #7
green_dragon37
Member
 
Registered: Oct 2002
Location: Lower Alabama
Distribution: Slackware, OpenBSD 3.9
Posts: 344

Rep: Reputation: 31
Huh, I had that come in about 2 weeks ago on the ezmlm list, and promptly deleted it.

--Ian
 
Old 01-22-2004, 07:21 PM   #8
r_jensen11
Senior Member
 
Registered: Apr 2003
Location: Minnesota, USA
Distribution: Slack 10.0 w/2.4.26
Posts: 1,032

Original Poster
Rep: Reputation: 45
Just a quick question:

what programs, if any, can be used to view the coding of the program?
 
Old 01-22-2004, 08:31 PM   #9
r_jensen11
Senior Member
 
Registered: Apr 2003
Location: Minnesota, USA
Distribution: Slack 10.0 w/2.4.26
Posts: 1,032

Original Poster
Rep: Reputation: 45
Okay, NOW I'm pissed off. Yahoo won't let me download it. I'm going to try to see if I can bypass their anti-virus somehow. Wish me luck!
 
Old 01-22-2004, 08:39 PM   #10
Thymox
Senior Member
 
Registered: Apr 2001
Location: Plymouth, England.
Distribution: Mostly Debian based systems
Posts: 4,368

Rep: Reputation: 64
Could you forward it to me as well please?

virus-analysis@thymox.uklinux.net

Cheecky email address, eh?
 
Old 01-22-2004, 08:47 PM   #11
Joey.Dale
Member
 
Registered: Jun 2003
Location: Tampa, Fl
Distribution: Gentoo, Slackware
Posts: 828

Rep: Reputation: 39
I too, would like to see what makes it tick I will not release it excipt on I quaerntined windows 98 box. (I want to se what it does) thank you joey.dale@elkenserver.net

-Joey
 
Old 01-22-2004, 09:10 PM   #12
r_jensen11
Senior Member
 
Registered: Apr 2003
Location: Minnesota, USA
Distribution: Slack 10.0 w/2.4.26
Posts: 1,032

Original Poster
Rep: Reputation: 45
Sorry guys, but Yahoo won't let me download it, forward it, or reply with it still as an attachment.
 
Old 01-22-2004, 09:40 PM   #13
r_jensen11
Senior Member
 
Registered: Apr 2003
Location: Minnesota, USA
Distribution: Slack 10.0 w/2.4.26
Posts: 1,032

Original Poster
Rep: Reputation: 45
Followup:

I think I might've found a backdoor through Yahoo's whole anti-virus check. I simply took the arguement out of the URL for the anti-virus when I copied the URL to download the file. The filesize is 15872(bytes?). At least, that's the number that registered under the filesize when I ran ls -co

If you guys want the file, I might be able to throw off the anti-virus checkers if I tarball it.
 
Old 01-23-2004, 11:03 AM   #14
r_jensen11
Senior Member
 
Registered: Apr 2003
Location: Minnesota, USA
Distribution: Slack 10.0 w/2.4.26
Posts: 1,032

Original Poster
Rep: Reputation: 45
Okay, after looking at "bagel" I've come up with some conclusions:
1.a) It's funny. It says that it cannot be run in DOS mode.

1.b) It should be called "beagle", not "bagel". Whenever it references to opening files(other than [%%random%%]) it refers to a file named "beagle.exe"

2) It appears that it doesn't affect Windows 95 systems. It modifies Windows systems by changing the regestry. Here's the string:
Code:
.calc.exe.open.SOFTWARE\Windows98.uid.SOFTWARE\Microsoft\Windows\CurrentVersio\Run.d3dupdate.exe.\bbeagle.exe.frun
If you guys want to look at it, email me, and I can try to arrange something. But remember, promise you won't do anything malicious with it!
 
Old 01-23-2004, 04:48 PM   #15
Joey.Dale
Member
 
Registered: Jun 2003
Location: Tampa, Fl
Distribution: Gentoo, Slackware
Posts: 828

Rep: Reputation: 39
Can it be run in wine?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Using Knoppix to scan Windows for Viri-How? tootlet Linux - Distributions 2 11-03-2005 06:38 AM
opening linux file system files in windows 95?? timefortea General 6 08-26-2005 01:28 PM
Opening or Executing files in linux from a windows Server rmarvin Linux - Networking 7 01-17-2005 10:32 AM
Problems opening xterm on linux from windows using xvision remote program starter c.santosh Linux - General 0 09-12-2004 12:46 PM
Opening a linux session remotely from windows? WarrenWright Linux - Newbie 12 02-04-2004 10:24 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 05:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration