around 10 or 12 years ago i found the "pif" tech. ...
the principle was easy, a .pif is handled as an executable, my idea was to include more things in the .pif.
structure was :
______________
pif commands ( & icon)
--
bat script
--
irc script
______________
When run as a .pif, the file copied itself as a .bat, adding an autostart, and copied itself as a .ini in irc client directory
When run as a .bat, the file could made many things
When load as a .ini (in irc client), the file was an irc backdoor
As you see, such "shortcut file" can include many different things or codes inside, playing with extensions only the linked code will be executed.
You can probably find some of thoses "pif worms" on vxnetlux. I've lost almost all the things i did.
Sadly my ".pif" idea was badly copied, all the worms or trojans using it were just .exe renamed, without editing the ".pif".
Last edited by Del_Armg0 (2011-11-11 15:03:44)