|
Subject: Virus Alert Please Read From: bill\sables Date: 19 Jul 01 - 04:14 PM I don't quite know what is happening but I have just has a number of emails returned which I never sent in the first place. These are from my Netcsape address. Included are Alice in Montana, Allan C, and Bert. I think someone has got into my address list soimehow and is sending these and they might contain a virus. Please don't therefore open any emails which seem to come from me with a netscape address Cheers Bill |
|
Subject: RE: Virus Alert Please Read From: bill\sables Date: 19 Jul 01 - 04:22 PM So far they only seem to have gone to people with names starting with A, B, and C. I will delete the entire address book to try to stop any others going out. Sorry about this. Cheers Bill |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 19 Jul 01 - 04:27 PM Bill, send me an e-mail. I can check what virus/worm you have and help you get rid of it. Click to e-mail me. Yes, I know what I'm doing. Plain text can't infect anything, and that's what I use. I also don't normally open attachements. Plus, if I get a message from you, I'll suspect it right off. If you don't want to do this, I'd recommend updating your virus protection software and running it. |
|
Subject: RE: Virus Alert Please Read From: bill\sables Date: 19 Jul 01 - 05:16 PM I recieved an email earlier today from Dick Greenhaus with an attachment. The message was as follows " I send this file in order to have your advice" When I opened the attachment it was a file about Spotlights on boats which I presumed was for one of Dick's nautical magazine articals. I then reciecved an email from Mike Cahill another mudcat member. I have phoned Mike and he said he didn't send it. I can only presume that the message from Dick contained a virus of some sort and it has taken over my netsccape account. So far it seems that my AOL account has not been affected I hope. All I can advise is for you not to open any attachment with the above message which seems to be sent from me. Thanks. Cheers Bill |
|
Subject: RE: Virus Alert Please Read From: Murray MacLeod Date: 19 Jul 01 - 05:34 PM Bill, I would investigate Sam Pirt if I were you. After all his web page does describe him as "irrestibly infectious" ! **BG** Seriously, I hope you get it cleared up, must be a real pain .... Murray |
|
Subject: RE: Virus Alert Please Read From: dick greenhaus Date: 19 Jul 01 - 05:42 PM Yes- I seem to have been smitten with a virus, which collects past E-mails and ships them out to random names from my address book. Bill described the text portion; there's also an attachment which has two consecutive filetypes (XX.zip.bat or something like that.) PLEASE DELETE ANY SUCH E-MAILS!! and please accept my apologies. dick |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 19 Jul 01 - 05:50 PM Bill, Dick and anyone else that got the "I send this file in order to have your advice" e-mail. You have something called "Sircam." Click here for the F-Secure virus description and help getting rid of it. |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 19 Jul 01 - 05:58 PM Basically, you'll need to download the thingie at the page above and run it. After that, you'll need to run an up-to-date anti-virus program. (This is a relatively new 'worm' and older programs probably won't recognise it.) F-Secure also have some free 'trial' anti-virus programs here. |
|
Subject: RE: Virus Alert Please Read From: bill\sables Date: 19 Jul 01 - 06:57 PM Thanks Jeri. Bill |
|
Subject: RE: Virus Alert Please Read From: Brakn Date: 19 Jul 01 - 07:13 PM I also got it. I can't open my mail "Outlook"....file missing...... Sirc32.exe: Will try your link Jeri |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 19 Jul 01 - 07:34 PM Please note - IMPORTANT:Don't delete the worm file 'sirc32.exe' before you run the program at the first link I posted. You will screw up your system.
According to the F-Secure site, what appears to happen is: The downloadable file at F-Secure should restore settings on your computer so Windows quits looking for the worm. After that, you can delete it. |
|
Subject: RE: Virus Alert Please Read From: bill\sables Date: 19 Jul 01 - 07:38 PM I just got another one with the same message from Allan C It seems we might all get it. Bill |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 19 Jul 01 - 07:52 PM I think you may be getting echoes. It went to everybody in Dick's address book. Allan C might have been in there, as well as Mike Cahill. Now Allan, Mike, and anyone else Dick sent it to could be unintentionally sending it to everyone in their address books. It's the attachment that's infectious. If you delete it without opening it, you shouldn't get infected.
|
|
Subject: RE: Virus Alert Please Read From: catspaw49 Date: 19 Jul 01 - 08:04 PM Received it this afternoon from dick g. Norton nailed it before I opened it. Spaw |
|
Subject: RE: Virus Alert Please Read From: Brakn Date: 19 Jul 01 - 08:17 PM By the time I got to Jeri's link I think I had already deleted the file. I couldn't get the downloadable file up and after trying for half an hour I rebooted and all seems to well. |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 19 Jul 01 - 08:19 PM Brakn, does the downloaded file work now? |
|
Subject: RE: Virus Alert Please Read From: Sorcha Date: 19 Jul 01 - 08:20 PM I haven't gotten it, but I downloaded and ran Jeri's file anyway. Will continue to check. |
|
Subject: RE: Virus Alert Please Read From: blt Date: 19 Jul 01 - 08:22 PM I got an email (from bill/sables) with an attachment which I stupidly opened--just a message about giving me some advice, and a bunch of song lyrics. I don't know if I've contracted a virus or not, my McAfee debugger, which I just updated, didn't detect any but I don't trust it. Can I run the program on the site you listed even if I don't have the virus? How can I tell that I have it? blt |
|
Subject: RE: Virus Alert Please Read From: McGrath of Harlow Date: 19 Jul 01 - 08:26 PM So basically if you don't open any attachments you're safe is it? |
|
Subject: RE: Virus Alert Please Read From: dick greenhaus Date: 19 Jul 01 - 08:29 PM Jeri- The link you provided carries the following warning: Warning! The system might become unusable if the worm's file is deleted without modifying the EXE file startup key first. After that the system can be safely disinfected with FSAV. If for some reason the worm's file can't be deleted from Windows (locked file), then you have to exit to pure DOS and delete the worm's file manually or use a DOS-based scanner (F-Prot for DOS for example). What means "modifying the EXE file startup key"? |
|
Subject: RE: Virus Alert Please Read From: MMario Date: 19 Jul 01 - 08:33 PM it's a registry hack - it could be manually fixed with regedit...but finding the correct location is the bugger. |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 19 Jul 01 - 08:35 PM You can run the program. I believe it just restores settings. If yours haven't changed it shouldn't do anything. This worm is quite new, and McAfee may not be that current. The F-Secure site appears to have added info on this one only yesterday.
After you run the downloadable program, look for the virus here: c:\recycled\SirC32.exe and delete that file (src32.exe) Also make sure you delete infected e-mail in in-boxes and out-boxes. I'm not really an expert on this, and I'm just 'winging' it. If anyone who knows better wants to jump in... |
|
Subject: RE: Virus Alert Please Read From: Joe Offer Date: 19 Jul 01 - 08:46 PM If you aren't expecting an attachment, don't open it. If you have any reason at all to question an attachment, e-mail the sender and ask about the nature of the attachment. If at all possible, avoid sending e-mail attachments. You can paste the text and sometimes the formatting of most documents into the text of e-mail messages, and they work just fine without the risk of carrying a virus. If you're on the Internet or if you share computer disks with anyone, keep your virus checker up-to-date. Have it set on "auto-protect" (or whatever your constant virus monitor is called). Also, scan your hard drive for viruses once a week. Most often, you get virsuses from people you know, people who don't even know they have a virus. This is true in life, as well as in computing... -Joe Offer- |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 19 Jul 01 - 08:48 PM McGrath, yes, you're safe from THIS virus. Dick, I tried to explain the startup thingie in this post.
"Modifying the EXE file startup key"?
|
|
Subject: RE: Virus Alert Please Read From: McGrath of Harlow Date: 19 Jul 01 - 08:51 PM "You can paste the text and sometimes the formatting of most documents into the text of e-mail messages, and they work just fine without the risk of carrying a virus."
I don't understand this stuff - but I hope there is something that stops people being able to post the code for viruses as part of the text of email messages... |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 19 Jul 01 - 08:56 PM McGrath, it's called a text-only browser. All those HTML-reading, script-enabling programs look good, but there are too many dangers. |
|
Subject: RE: Virus Alert Please Read From: Justa Picker Date: 19 Jul 01 - 08:57 PM Since 99.9% of these viruses appear to be written for Outlook, why would anyone want to continue using this e-mail program? It baffles me. Eudora doesn't get hit with these viruses. I also use Norton Anti-Virus (and get Live Updates bi-weekly). I set my incoming attachment directory in Eudora so that any and all attachments come into C:\Norton AntiVirus\Quarantine\Incoming. ANYTHING attached or downloaded that comes into my computer goes to that directory. I also use Zone Alarm Pro, and it has a very handy feature that automatically renames the extensions of any executable file (plus other file extensions I can manually add) so that there is no way I can accidentally open an executable attachment, should I have a moment of laxness. |
|
Subject: RE: Virus Alert Please Read From: Amergin Date: 19 Jul 01 - 09:10 PM Popel use OE, because it is there...they are ignorant of other email programs...and plus some ISPs do not support anything else... |
|
Subject: RE: Virus Alert Please Read From: catspaw49 Date: 19 Jul 01 - 09:18 PM Awhile back I got hit and was hitting folks with the kak worm. I couldn't understand until I worked with the Symantec Help group. They analyzed my stuff and it turned out to be a defective Disc. I downloaded a new program from their site free of charge and and have been a happy camper since. Symantec/Norton is generally pretty quick with the calls and the fixes (or quarrantines) and they were great to work with. I agree about Outlook, but I also killed the features and ise it in text only. I download definitions once a week and also have the auto-scan set up for every Friday. With the amount of crappola out there, it seems prudent and really takes very little time. I suppose I should go to another ptogram like Eudora, but............ Since the Norton has been up properly, I've had no problems and it's nailed quite a few incoming problems including internet site problems where it will close down the offending site. Great company. Spaw |
|
Subject: RE: Virus Alert Please Read From: blt Date: 19 Jul 01 - 09:20 PM Well, I did open the email and attachment, but as far as I can tell, I didn't get the virus. I followed the directions on the website and then tried to find the sir32exe file, but couldn't find anything. I also deleted the email and sent warning messages to people on my address list. If I can't find the virus using the file finder, can I trust it's not there? Would it hide in some devious way? blt |
|
Subject: RE: Virus Alert Please Read From: katlaughing Date: 19 Jul 01 - 09:21 PM So how does InnoculateIT compare to the programs you've pointed us, too, Jeri? So far the only email I've received from BillSables is from his aol addy telling us not to open anything from the other. Thanks, kat |
|
Subject: RE: Virus Alert Please Read From: katlaughing Date: 19 Jul 01 - 09:39 PM I am running InoculatIT right now. It seems to be doing a thorough job EXCEPT there are several different files which it says it cannot open and thefore has not scanned. Any advice? Thanks, kat |
|
Subject: RE: Virus Alert Please Read From: Brakn Date: 19 Jul 01 - 10:00 PM Jeri Still can't get the downloadable file. |
|
Subject: RE: Virus Alert Please Read From: Alice Date: 19 Jul 01 - 10:18 PM Another reason I love my Mac... the attachment wouldn't open. The email virus from Bill's email address was called "John Carey", and later in the day, the same type of email with attachment came to me from Allison, called "Chocolate". Apparently the name changes, although the same attachment is being passed on through the address books of mudcatters. Alice |
|
Subject: RE: Virus Alert Please Read From: Justa Picker Date: 19 Jul 01 - 10:20 PM Thanks to the "clone" for mending my html. |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 19 Jul 01 - 10:22 PM I haven't used the anti-virus on the F-Secure site, but it's free. InnoculateIT isn't available for download anymore, although they say they'll keep doing updates. It can't open files you have open, and there are always some logs and things open. I usually just ignore that message. (I don't know if I'm right to do that.) Brakn, I'm at a loss. If it were my computer, there are some things I'd try, but I wouldn't adivise others to do them. I don't mind taking a risk on my own system, but... There may be more info at other sites about the worm "sircam," or some other folks here may be able to help. I'll try looking tomorrow if nobody's posted a fix. |
|
Subject: RE: Virus Alert Please Read From: alison Date: 19 Jul 01 - 10:37 PM yep... yesterday I got it from dick, (but it wasn't his usual style of writing so I was doubtful... and Norton picked it up anyway), today I got it via bill sables and allison(again not their usual style of writing).... they had "John Carey", "Chocolat" (dick's one had no name on the file........... all were picked up by Norton....... looks like if you receive anything from a mudcatter over the next few days you should be very wary....... slainte alison |
|
Subject: RE: Virus Alert Please Read From: katlaughing Date: 19 Jul 01 - 10:37 PM Thanks, Jeri, that's what I've been doing, too, ignoring those ones.:-) I've also noticed that when I open InoculateIT, it tells me to upgrade, so I do and it takes about two seconds and tells me my files are up-to-date. It doesn't seem as though it is really doing anything. SYMANTEC has some information on this virus, too. kat |
|
Subject: RE: Virus Alert Please Read From: Uncle Jaque Date: 19 Jul 01 - 10:41 PM Here is the link to SYMANTEC (NORTON) Anti-Virus site concering this Worm; http://www.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.html They put it up on 07/14.
|
|
Subject: RE: Virus Alert Please Read From: alison Date: 19 Jul 01 - 10:44 PM the thing that worries me is that the one from dick was titled "add tune" as if someone knew it would be something to send to me.... is someone we know targetting us? slainte alison |
|
Subject: RE: Virus Alert Please Read From: katlaughing Date: 19 Jul 01 - 11:37 PM Good question, Alison. It would be one way for someone to get to a lot of us, wouldn't it? |
|
Subject: RE: Virus Alert Please Read From: Sorcha Date: 19 Jul 01 - 11:41 PM That thought occured to me also. Sort of a gut feeling you're right....... |
|
Subject: RE: Virus Alert Please Read From: Bob Bolton Date: 20 Jul 01 - 12:51 AM G'day Alison, The one I got from Dick had "OLSEN" as its heading and the attachment came in as OLSEN.ZIP.bat ... but I suspect that was what was mentioned way above - my ZoneAlarm may have changed the ~~~.exe to ~~~.bat. I had advised Dick that anything with two stops in it is highly suspicious ... and corporate firewalls have been advised to delete or disarm any such files. In regard to the "Add Tune" heading, I think the bug selects keywords or titles from past e-mails of the victim, so they look authentic (rather than this being some disgruntled GUEST attacking Mudcat with a custom virus) ... I think ... Regards, Bob Bolton (heading off to run that de-bug file ... just in case.) |
|
Subject: RE: Virus Alert Please Read From: BlueJay Date: 20 Jul 01 - 02:44 AM I haven't received the virus, (yet), on either my home computer or the computer at work, both of which are in various Mudcat address books. Thanks, Bill Sables for the e-mail warning, which I'm sure many of you received. And Allan C., I stand in awe of your efforts to stop the spread of this virus, to wit: your phone call warning of this virus and the link to the Mudcat. Jeff, (to whom you spoke at PooTwa's house), relayed the message immediately. We are not affected so far, but thanks to all of your efforts I can be on the lookout. Allan, your phone calls are above and beyond the call of duty, and very greatly appreciated. My apologies to GUEST for having participated in a non-music thread,thanks, BlueJay. ") no that's not it %} that's better, %O, my Ralph Steadman imitation. :) |
|
Subject: RE: Virus Alert Please Read From: AllisonA(Animaterra) Date: 20 Jul 01 - 07:00 AM Yup, I got it, I opened it, and spent last night trying to debug it, not having read this yet! I just ran the F-secure de-bugger and will check Outlook soon to see if there's been any effect. What worries me is that the attachment from Dick was a kids song- I didn't quite know why he would run it by me but it seemed perfectly innocent at the time, since spend so much of my time singing with kids. Jeri, once again you-da-woman! Thanks for the link- now I'm off to see if it worked! |
|
Subject: RE: Virus Alert Please Read From: AllisonA(Animaterra) Date: 20 Jul 01 - 07:19 AM I seem to be clean; after I updated Norton it cleaned it up. And I thought it was ok to open attachments from people you know and trust! Now I know better, after reading all the dire warnings from posters above. Thanks- and I'm heading to Norton to set up Autoscan! |
|
Subject: RE: Virus Alert Please Read From: bill\sables Date: 20 Jul 01 - 07:27 AM It seems the best way , if we are sending emails to each other with attachments, is to send an email first and tell the recipient to expect it comming and state a codeword in the title. I have decided, if I get anymore attachments, to contact the sender to verify if it was realy sent. Bill |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 20 Jul 01 - 07:47 AM For folks who deleted the worm/virus before making any other changes, the site kat gave the link to has detailed instructions on how to fix your system, which involves all of the following:
Deleting any attachments from infected e-mail. Again, check the site before doing any of this. Consider editing the registry key as doing brain surgery on your computer. If you mess with the wrong thing, your computer's screwed. Note that running the file from F-Secure (I posted the URL above) is a whole lot easier for non-technogeeks. It does the complicated stuff for you, and all you have to do is delete the worm files.
It appears as though the worm grabs a file already on the sender's computer to hide in, and titles the message to be the same as the attachment. It's not surprising Dick would have music files. If it has two file extensions as Bob Bolton mentioned, it's likely to be the worm. ('file.ext.ext' instead of the normal 'file.ext')
|
|
Subject: RE: Virus Alert Please Read From: catspaw49 Date: 20 Jul 01 - 07:55 AM I received two and perhaps as you said Jeri, there are some ghosts or whatever. What I wanted to mention though is that one was infected and the other was not and reading through all the "F" and Sym/Nor info, there is a reference several times to the 1 in 33 chance of being infected. Spaw |
|
Subject: RE: Virus Alert Please Read From: Sorcha Date: 20 Jul 01 - 01:32 PM Sorcha is still worm free, feel free to use my e mail. |
|
Subject: RE: Virus Alert Please Read From: Uncle_DaveO Date: 20 Jul 01 - 01:53 PM At the insistence of my computer tech, I bought and installed Norton Internet Security about two weeks ago. Since then it has caught and neutralized six attachment-borne viruses. On the other hand, I've not actually had any problems with viruses in the past, for two reasons: I used Netscape, not Outlook, and I've been VERY careful about opening attachments. Dave Oesterreich |
|
Subject: RE: Virus Alert Please Read From: pavane Date: 20 Jul 01 - 02:21 PM Looks like I received it too. From digitrad, supposedly. A file called horserun.zip.pif, but I looked at it using HEX editor and it was a windows executable, not a zip at all. Probably wouldn't have harmed, as I am using WIN95, and I think the worm needs at least WIN98. |
|
Subject: RE: Virus Alert Please Read From: Mrs.Duck Date: 20 Jul 01 - 04:10 PM Just got a e mail from Bills AOL account under the heading @No subject@. I didn't open it in view of the above but it could be that it is now affecting all his e mail accounts. |
|
Subject: RE: Virus Alert Please Read From: Steve Latimer Date: 20 Jul 01 - 09:16 PM I just got it. The title of the e-mail was "Lawyers", it was from a person I've never heard of it. I read the text and it was the "advice" one referred to earlier. I scanned it just to be sure and it was a worm. I deleted it. Bill, thanks for bringing it to our attention. |
|
Subject: RE: Virus Alert Please Read From: Bill D Date: 20 Jul 01 - 09:37 PM the email from Dick tried to come see me earlier, but I looked at it in a program that does NOT put it on my machine. I use an email checker that reads my mail ON THE SERVER without actually downloading it...and allows me to delete it without it ever getting to my machine. (it was full of weird code, and had that double ending on it..,zip,ife or whatever Then I have Norton....then I have 2 firewalls..... and I would not use Outlook Express if you paid me!..I use Eudora, or Calypso, or Pegasus, or the email reader in Agent... is all this overkill? perhaps, but even if I am sleepy and careless, all those safeguards scream at me if I even try to open a zip or an .exe without knowing exactly where they came from! |
|
Subject: RE: Virus Alert Please Read From: Amergin Date: 20 Jul 01 - 09:44 PM i love eudora....but there again many folks are ignorant of it...and plus the isps do not support it....at least we don't...we only support OE...and a couple of earlier versions of netscape... |
|
Subject: RE: Virus Alert Please Read From: dick greenhaus Date: 20 Jul 01 - 09:45 PM I'm sorry about the trouble my virus seems to have caused. Thanx to Jeri's helpful advice my system is once again pure--THANX JERI!---and all is well again. Be careful, though. Some other Mudcatters may have been infected. |
|
Subject: RE: Virus Alert Please Read From: Bill D Date: 20 Jul 01 - 09:58 PM WHY in the name of all that might be Holy, would an ISP not support Eudora and other such well known and decent email programs? Why & HOW can they deal only with Outlook & Netscape? I suppose I am lucky to have choices in an urbam center, but I'd have a WEB-based email only before I'd put up with that sort of narrowness! [I thought that any program that followed certain protocols(IMAP...etc..) would work with almost any ISP!..strange!] |
|
Subject: RE: Virus Alert Please Read From: Justa Picker Date: 20 Jul 01 - 10:03 PM When I first got on the Internet back in '95, my ISP gave me an installation software package, that had a shareware version of Eudora. I've been with it ever since, although I have tinkered with the other email programs, but never liked them. There's a certain elegance about Eudora. While I can appreciate the appeal of using a program that integrates email, newsreader and web browser all in one (as in Netscape Communicator, or IE/Outlook) I prefer to keep and maintain control over all my net apps, independently of each other. I don't worry about "wasting resources" because I have a speedy machine, large/fast hard drive, and more ram than I'll ever use. So it's Eudora for email, Nomad NewsReader for usenet, and IE for browsing. Usually I'm only running two of these three in the background at any given time. I'd switch back to Netscape if they could actually write a non buggy browser version that doesn't crash everytime upon booting, and then having to relaunch it (whereupon it stays up.) |
|
Subject: RE: Virus Alert Please Read From: Allan C. Date: 20 Jul 01 - 10:10 PM This was my first (and I hope last!) encounter with a virus. I think that I was able to rid my computer of it before the virus was sent to everyone on my email list. So far, Bill seems to have been the only recipient of a virus-laden email from "me", or more accurately, from the virus. Sorry, my friend. I hope nobody else on my list encountered any problems by way of my computer. The computer appears to be back in order again and no real damage was done to it. This is not an experience I would wish upon anyone. It feels to me much as it must feel to have one's house broken into and to be robbed. If nothing else, the virus certainly robbed me of a huge chunk of time. Bummer, man! |
|
Subject: RE: Virus Alert Please Read From: Amergin Date: 20 Jul 01 - 10:37 PM Bill, the reason why we don't support other email programs is that we don't supply them.... |
|
Subject: RE: Virus Alert Please Read From: Justa Picker Date: 20 Jul 01 - 10:49 PM Any email program using POP3 protocols will work with any ISP. It's a simple matter of entering the mail (SMPT) server name used by your ISP, your email address, your logon i.d. and password . Input this info in ANY email program and it will work. I have cable internet. @Home gives you this "installation" CD "to make everything work". Thing is, if you're a little computer savvy you don't need any of it, unless you want to be bombarded with advertising and cookie transponders, from those that are in bed with the ISP. All you need to do is go into "Network Neighborhood" and under "Indentification" enter your user assigned name (usually a combination of letters and numbers) and the name of the workgroup (which is "@home") and then just tell your browser you connect through a LAN (without proxy settings detected), enter the stuff for your email program, and away you go. Problem is the cable ISP's make it a little cumbersome because they want you to use their software and browser versions. You have to do a bit of digging on the tech support website, to get the info to input for SMPT and NewsServer useage. |
|
Subject: RE: Virus Alert Please Read From: Francy Date: 20 Jul 01 - 10:50 PM I just received two from Dick with the same message needing my advice with an attachment. I immediately deleted both without opening the attachment....My last name starts with J....thought i'd alert you all. |
|
Subject: RE: Virus Alert Please Read From: katlaughing Date: 20 Jul 01 - 11:09 PM Allan, it was so good of you to pass the word on by phone. Thanks too, to Jeri, Justa Picker and others who've posted good information here. I am rethinking our use of OE through @Home, now. So far, we've been okay and not received anything untoward. Thanks, kat |
|
Subject: RE: Virus Alert Please Read From: Grab Date: 20 Jul 01 - 11:10 PM Never got on with Eudora, mainly bcos I have (or had) several dial-up ISP accounts, and changing from one dial-up number to another was a pain. The best for that is Pegasus, the only trouble is that it's getting rather old now. Apparently the v4 beta of Pegasus is on its way soon - I'm looking forward to trying that out. The main thing I have against Outlook (apart from its crap security) is that it's designed for beginners with no regard for experienced users. You want to do anything complex, you really have to fight it to get it to do what you want. Oh, and crap ideas like integrating web and file browsers in there for god knows what reason. Graham. |
|
Subject: RE: Virus Alert Please Read From: Amergin Date: 20 Jul 01 - 11:48 PM well, I can imagine we'll be getting calls related to this thing soon... |
|
Subject: RE: Virus Alert Please Read From: DonMeixner Date: 21 Jul 01 - 12:24 AM I have had no end of grief with this. I used the F_Secure hook that Jeri supplied and I think its cured now. Hope its not in my office box. Don |
|
Subject: RE: Virus Alert Please Read From: campfire Date: 21 Jul 01 - 01:58 AM I got it too, from Dick, on a file called Joe May 1. I'm hoping that since my computer wouldn't open it, I didn't get it. I deleted all the addresses in my address book; can I assume then I can't spread it, or can it read addresses on e-mails I've saved, too? I'm downloading Jeri's suggestion as I type this. If it can read addresses on e-mails, a bunch of spammers are in for it, cuz I didn't empty my "trash" folder lately!! campfire |
|
Subject: RE: Virus Alert Please Read From: Brakn Date: 21 Jul 01 - 08:44 AM Just got rid of it! |
|
Subject: RE: Virus Alert Please Read From: Brakn Date: 21 Jul 01 - 08:47 AM EErrrrrrrr I hope. |
|
Subject: RE: Virus Alert Please Read From: bill\sables Date: 21 Jul 01 - 08:54 AM I just got another one from Annimetera Bill |
|
Subject: RE: Virus Alert Please Read From: George Seto - af221@chebucto.ns.ca Date: 21 Jul 01 - 09:05 AM I can't remember who thought it was silly of me not to use a more "advanced" browser and "e-mail". I use the Lynx Text Browser and the Pine Mail Reader. I don't get these things in the e-mail. I couldn't even save the attachment. Good luck everyone. I hope everything comes out right. I have had 3 other people send me the same thing, Actually, one of them wound up being 5 times the size of the others. |
|
Subject: RE: Virus Alert Please Read From: Bill D Date: 21 Jul 01 - 09:30 AM Thanks to JustaPicker for clarification of some things..(Amerigin...I was confused by what you meant by 'support'....I am assuming now that you mean programs that YOU actually provide copies/versions of in your installation package and will answer questions about) for anyone who wants to reconsider their Email client, here are 3 useful ones which are currently voted the best in their categories by the 'freeware' newsgroup. There ARE other choices, and as mentioned, Pegasus is soon to be upgraded again. |
|
Subject: RE: Virus Alert Please Read From: Bill D Date: 21 Jul 01 - 09:41 AM here is the program I use to look at, and if necessary delete mail BEFORE it is ever on my machine..... |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 21 Jul 01 - 09:57 AM Before I start repeating myself, one more comment: This virus/worm doesn't infect just an e-mail program, it infects Windows. Bill, and everyone else who's got it, you're gonna keep sending it until you get it off your computer. One more time with feeling - and this is IMPORTANT!!!
You have to repair the damage the worm has caused.
You have to get rid of the worm. The important things: 1) If you repair the damage the worm has done without removing the worm itself, it appears you will re-infect yourself every time you run a program. (I'm guessing on that last bit.) 2) If you remove the worm without repairing the damage, either before or after, your computer may not work properly.
HELP is here:
|
|
Subject: RE: Virus Alert Please Read From: Eric the Viking Date: 21 Jul 01 - 12:14 PM Looks like it got to "L" the next message after Bills was from"DicK'@digitriad" asking for advice. Deleted it without opeing, and am just about to live update from Norton. cheers Eric |
|
Subject: RE: Virus Alert Please Read From: Amergin Date: 21 Jul 01 - 01:56 PM BillD, you would be correct.except that it is not me who supplies the software....just the company I work for....and the reason we don't really support netscape much anymore is because they got bought by AOL....a competitor.... |
|
Subject: RE: Virus Alert Please Read From: GUEST,Mike Cahill Date: 21 Jul 01 - 02:16 PM Arn't I the popular one? I've not looked at my mail for about 24 hours, and I've just had to delete 22 copies of the virus. |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 21 Jul 01 - 02:20 PM Mike, nobody loves me at all. I've not received it once! Of course, my ISP may be blocking it, but I feel so left out... |
|
Subject: RE: Virus Alert Please Read From: Richard Bridge Date: 21 Jul 01 - 02:36 PM There's lots of good stuff here but two questios are screaming to be asked - but no-one yet has. 1. Which is the best anti-virus program to use? There are three essential qualifications. It has to be free. You have to be able to update it online (free) and it has to scan incoming email and downloads automatically. I used to use McAfee which seemed to work well - but I had got it free with an electronics components catalogue about 3 years ago, and updated and upgraded it free when the downloads were available free on the McAfee site - and then I had a crash and after 7 format Cs and a week on the phone to VIglen support I sent the computer back (they decided that was cheaper than the telephone support!) and I had to buy a new one to use whil the old one was back. I have not set the old one up again yet and trying to get validation on the old McAfee in order to get, free, back to where I had been would have ben just too much hassle. The I got a disc with a free InoculateIt on it but I could not get the damn thing to run or download updates at all so I junked that. Currently I have an obsolete Norton engine with up-to-date definitions, but to upgrade the engine would cost money, so I am thinking about trying Command (again of a free disk. Comments? The next is what email client to use. My ISP (Btinternet)will only support Outlook Express (and I suspect advice they gave me of causing my great crash) but I run Outlook (full version) 2000. I run Outlook because I want to get my incoming faxes to come up in the same inbox as my incoming emails - which Outlook 97 used to do fairly well with WinFax, and in theory Outlook 2000 ought to do with Symantex fax basic edition which was writtten for the purpose, but the only time I got it to work it would not let me print the fax. So I am likely to go back to Outlook 97 and perhpas Win 95 as it seems to be more stable than Win 98. I used (when I was running WIn 95) to run Bitware 3.0 to answer the telephone on a differnent line on com3, with faxes and data coming on on com2 but noe of this has ever worked with Win 98 and Office 2000. I would really, really like to get back to having my phone, fax, and email all showing in pretty much the same place on my desktop. Any suggestions? If that's too hard, what will let me recieve email and faxes in the same inbox Oh, you guessed it, it wants to be free. |
|
Subject: RE: Virus Alert Please Read From: Amos Date: 21 Jul 01 - 02:37 PM Just as a comment, notice the fraudulent attachment name. The same gimmick wa sused on the Love Letter virus. The REAL file suffix is ".bat" which means it is an executable command-line batch file that will run when called. The ".zip" is a fraudulent string put in the name to make you think it looks like an ordinary attachment of the type people send each other often. Not that we of the Mac world need to worry on this sort of crap -- we don't use openly accessible regisitry architecture the way the WinTel users do. But we're getting more vulnerable with the BSD migration starting with the "new advanced and improved" OS from Apple, which really is much better functionally, but could be more vulnerable to this kind of cyberviolence. A |
|
Subject: RE: Virus Alert Please Read From: clansfolk Date: 21 Jul 01 - 02:56 PM Add us to list - email with the "I send this file in order to have your advice" arrived yesterday - Norton's caught it although we never open email attachments and everyone who knows us is aware not to send them!
Only the one as above as yet but Simon recieved another one on his private account the other day. All were dispatched to the bin without b3eing opened a bit like the rest of the junk mail we get through the post!! Be alert - we need more lerts! :-)
|
|
Subject: RE: Virus Alert Please Read From: katlaughing Date: 21 Jul 01 - 03:07 PM I downloaded the new Norton 2001 AntiVirus, it screwed up all my connections, couldn't get online or email, and I had to spend an hour on the phone with tech support @home to get it straightened out. I had it set to automaticlaly check my email before it comes into my box, BUT it wasn't letting me get ANY, so they told me to disable Norton, altogether. Any advice on what I can do so that doesn't happen, again, if I activate Norton? Also, do I need Norton if I have InoculatIT or vice versa? Thanks, sorry of these are redundant. kat |
|
Subject: RE: Virus Alert Please Read From: Justa Picker Date: 21 Jul 01 - 03:19 PM Richard, I can't advise you on an e-mail client which will cover all the bases you've mentioned. You obviously want to be able to have your cake and eat it too. Nothing wrong with that, in a perfect world. :-) But sometimes, security and prudence in maintaining that security comes at a price, whether through the minor inconveniences of running separate programs to accomplish what you need. I use Eudora for e-mail, Delrina Winfax 7.0 (because every version they've brought out since 7.5 is dogshit i.m.o especially version 10)for fax purposes, and Norton Anti Virus. In my opinion Norton is head and shoulders above all the others, because of it's ability to catch viruses that McAfee and Thunderbyte and some others miss. I've been infected in the past using McAfee while lulling under a false sense of security. I've not had that problem with Norton, and it's Live Updates. Yep, you'd have to pay for Norton, but for the security and peace of mind it provides, it's worth it, and why should any software company provide software services, support and updates free? You get exactly what you pay for. Just my $0.02 |
|
Subject: RE: Virus Alert Please Read From: catspaw49 Date: 21 Jul 01 - 03:20 PM Sorry kat...After my initial disc problem, my download of Norton has worked fine and reads the mail first. when I had the problem, they couldn't have been better. Hmmmmm......... Spaw |
|
Subject: RE: Virus Alert Please Read From: katlaughing Date: 21 Jul 01 - 03:50 PM Thanks, Spaw, I think JP has it figured out for me; he just sent me some instructions I will work out a bit later. Thanks, JP! |
|
Subject: RE: Virus Alert Please Read From: DonMeixner Date: 21 Jul 01 - 05:13 PM I will admit that I haven't read this entire posting, been too busy deleting mail and trying to get controll of my computer. Excuse me if I'm naive about computers but can we delete our current address books to stop these continual mailings, clean our personal files, and rebuild our mail lists again. I have had mail from people I have never met asking who I am and why have I contacted them. Other people I have never heard of are thanking me for the virus. I think my end of the wire is clear now, but I keep getting hits. We need to devise a method where by we don't pass it around between ourselves at least. Don |
|
Subject: RE: Virus Alert Please Read From: Clifton53 Date: 21 Jul 01 - 05:20 PM I got the bloody worm from Dick G and foolishly opened it as well, then, since I could not read it, it was all code, I replied and sent it back to him. Sorry Dick, I should have known better.
How can one tell if one has this virus? I'm using Windows 95 as well. Problem is, about all I do on a computer is type. Clifton |
|
Subject: RE: Virus Alert Please Read From: catspaw49 Date: 21 Jul 01 - 05:41 PM Clifton, please go back and read Jeri's links. Spaw |
|
Subject: RE: Virus Alert Please Read From: Justa Picker Date: 21 Jul 01 - 05:52 PM And that method where by we don't pass it around between ourselves at least, Don, is to immediately quit using Microsoft Outlook...since as I've written before, 99.9% of all e-mail related viruses are written for it, and exploit its address book. Why should you have to delete your address book? Between Bill D., Jeri and myself, we've presented good alternatives. So it takes you an extra 15 minutes to learn a new e-mail program. Isn't the added security worth it? |
|
Subject: RE: Virus Alert Please Read From: Bill D Date: 21 Jul 01 - 06:00 PM here is probably the highest rated FREE anti-virus, now that InoculatelT has become a paid item... AVG Antivirus the DO have update on this virus on the site! here's a quote from the newsgroups... "I have AVG for 2 years and it is great... It has effective caught about 7 or 8 virii when being attached to email.. They also have periodic updates to deal with the new virii being released. " |
|
Subject: RE: Virus Alert Please Read From: Bill D Date: 21 Jul 01 - 06:24 PM funny, Symantec/Norton is not answering right now, but here a cut-n-paste from AVG about the virus Another mass mailing worm started to spread. It is a 134kB "whale", written in Delphi. Judging from encoded texts it comes from Mexico: [SirCam Version 1.0 Copyright (c) 2001 2rP Made in / Hecho en - Cuitzeo, Michoacan Mexico] The text is even included in following "diet" version: [SirCam_2rP_Ein_NoC_Rma_CuiTzeO_MicH_MeX] It sends itself be an email with the subject containing the name of an attached file and the body composed from following sentences: Hi! How are you? See you later. Thanks I send you this file in order to have your advice I hope you can help me with this file that I send I hope you like the file that I sendo you This is the file with the information that you ask for If user's preferred language in Windows is Spanish, the worm can adapt itself to the fact: Hola como estas ? Nos vemos pronto, gracias. Te mando este archivo para que me des tu punto de vista Espero me puedas ayudar con el archivo que te mando Espero te guste este archivo que te mando Este es el archivo con la informacion que me pediste The attached file is created from the main worm body and a randomly selected file (an archive, a document or an executable) coming from the infected computer. The original name of the file is preserved, the worm justs attaches another extension (pif, lnk, bat and com) to it. When run, the worm copies itself to various folders under different names: SirC32.exe, SCam32.exe, SirC32.exe, ScMx32.exe, Microsoft Internet Office.exe and rundll32.exe Then the worm re-creates the copy of the carrier file and if it is the EXE file it is instantly run. For other file types it tries to locate the corresponding application for opening the file: the WinZip for .zip files, Excel for .xls files and WinWord (or WordPad) for .doc files. The worm tries to ensure being regularly run by creating a Value 'Driver32' in the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\ and by a modification of the key HKCR\exefile\shell\open\command (the same trick as I-Worm/PrettyPark). As the majority of new viruses, this one can spread itself to shared folders on the local network. It prefers the folders \recycled and \windows on network-mapped disks and secures its re-run by writing a line @win with link to the virus file to the file \autoexec.bat or by replacing system file rundll32.exe with its own copy. |
|
Subject: RE: Virus Alert Please Read From: Bill D Date: 21 Jul 01 - 06:35 PM oh, sorry, for those members in mainland Europe, I should have noted this about AVG "Important notices AVG 6.0 Free Edition is available in English language only. AVG 6.0 Free Edition offer is not valid for European users, except the users coming from United Kingdom. For these users we offer a free download of a 30-day Trial version of AVG 6.0 Standard Edition for their evaluation purposes - see more information below. NO TECHNICAL SUPPORT IS AVAILABLE WITH AVG 6.0 Free Edition. Please see our support offer for AVG 6.0 Free Edition here. |
|
Subject: RE: Virus Alert Please Read From: catspaw49 Date: 21 Jul 01 - 07:26 PM Just wondering here.................... I wonder how many 'Catters who WOULD NOT NORMALLY OPEN THIS THREAD have received this from either source? Assuming the address book made it to "F" that is possibly quite a few! I got the message as I said from dick and I didn't check at the time whether I was under Patterson (making it P) or Catspaw. In any case, there are some who may not be aware at this point.........maybe? Spaw |
|
Subject: RE: Virus Alert Please Read From: CarolC Date: 21 Jul 01 - 07:39 PM I had a problem with Norton, too. I just had a new hard drive put in my computer, and upgraded my windows and ISP software. I installed the Norton Internet Security 2001, and it messed up my computer. I deleted the Norton, and I still can't get my computer to recognize more than 12 colors, but I was able to regain my internet access at least (which I had lost temporarily). I have not recieved any e-mails with the virus that I know of. And I haven't called any tech support yet to see what the problem was with Norton. I'm kind of overwhelmed with new things to learn right now, because the upgrade means I need to learn a whole new way of using my computer. |
|
Subject: RE: Virus Alert Please Read From: katlaughing Date: 21 Jul 01 - 07:44 PM Spaw, at least everyone who was on Bill Sables' email list received a notice from him about, as he sent it out on his aol account early on. Still, I suppose there are some who have missed it, still. |
|
Subject: RE: Virus Alert Please Read From: catspaw49 Date: 21 Jul 01 - 08:00 PM Good point kat. The virus infected e-mail came to me from Dick and not Bill. I got the letter from Bill, but nothing from Dick.............I dunno....at this point, probably anyone who got it knows it so it was just an idle thought...... Spaw |
|
Subject: RE: Virus Alert Please Read From: Peter K (Fionn) Date: 21 Jul 01 - 08:36 PM Tom Lehrer saw this coming. CLICK HERE (make sure your speakers are on) for a relevant page, on a brilliant site. There are one or two misunderstandings floating around in this thread. In particular, Jeri, you need to know that there are viruses around now that do NOT require file attachments to be opened. One such that is rampant at present is known as MTX.9244. This proliferates as a trojan and a worm. The trojan element manifests itself as an incoming email with no subject, no message and a file attachment that is gobbledegook and can't be opened. It arrives simultaneously with a genuine email from someone already (and usually unknowingly) infested, and claims to be from that same person. At this point, if you're using Windows with OE or Navigator, your system is already infested. Moreover it will crash if you try to download, access or run McAfee or Norton or even go to their sites. As far as I know, Command is the only solution to this one, and costs about 20 bucks I think. But you'll also have to edit your registry file in line with their instructions. Also you'll probably need to reinstall winsck.dll and any other files the virus has over-written. Surely it is only a matter of time before we're all walloped by something really clever. Those dependent on Windows and OE are certainly the biggest targets. Justa Picker looks well defended, but for good measure I'd have the linux/Opera combination standing by on a second hard disk. . Bill and Justa Picker, where ISPs say they don't support certain email packages etc, what they usually mean (but don't say) is that these packages will run fine, but that their helpdesks aren't trained to give you any help. |
|
Subject: RE: Virus Alert Please Read From: Justa Picker Date: 21 Jul 01 - 08:54 PM Points well taken. Thanks Fionn. |
|
Subject: RE: Virus Alert Please Read From: Jeri Date: 21 Jul 01 - 09:18 PM I thought it was clear I was only talking about having to open the attachment to get this particular worm. Maybe not. In any case, I agree with Fionn, who knows a lot more than me on this subject. E-mail programs that read HTML and run the embedded scripts are extremely susceptible. (Does "kak" sound familiar?) Good song, by the way! |
|
Subject: RE: Virus Alert Please Read From: dick greenhaus Date: 21 Jul 01 - 10:39 PM First: Thanx Jeri! I'm clean again Second: Apologies to anyone who's gotten an infected message from me. Third: I got the damn thing from someone. A fast fix is to avoid sending me attachments. I realize that this can slow things down when compared to the speed of transmitting non-text files (.ZIP, .JPG etc.) but I don't think the speed is worth the risk. I'll take my chances with .NWC and .MID files, but they're about the only ones that can't be exported as text, then cut and pasted into the body of the E-Mail. And if your E-Mail program won't do this, SHOOT IT!.
|
|
Subject: RE: Virus Alert Please Read From: Jande Date: 22 Jul 01 - 03:22 PM I haven't run OE for many many years. I prefer Pegasus (even though it does have a couple of r *irritating* habits). I just wanted to remind some of the OE and Windows users that the default setting in the Windows Operating System has file extensions turned off. That is the reason the worm has two .extensions. wormname.zip.bat. It's written that way to fool inexperienced Windows users into thinking the file that has arrived is called wormname.zip. The default windows setup hhides the last dot and three characters in a filename. If I Remember Correctly, This default setting can be changed by double-clicking on My Computer Icon and choosing View|Folder Options then in the view tab, under Files and Folders, click the square box to remove the check mark before Hide file extensions for known file types. Now you should be able to see all file extensions,including any double ones that *may* be some kind of virus. Hope this helps someone... ~ Jande |
|
Subject: RE: Virus Alert Please Read From: Bill D Date: 22 Jul 01 - 03:36 PM I unchecked that box a LONG time ago...I hate it when I can't see exactly what is there. I always show the 'detailed' view of all directories, so that all data and settings are clear...I can hide or change anything I want IF it ever seems temporarily useful to do so.... I truly hope this set of recent problems does no lasting damage to anyone, and encourages those who had a scare to go through the process of protecting themselves and learning as much as they can about their computers. Basic virus protection and control over settings and features is just good insurance. It's sort of like your car...you don't have to be a mechanic or understand physics to learn to change the oil and check the water level in the radiator.(maybe catspaw has better metaphors!) |
|
Subject: RE: Virus Alert Please Read From: Uncle_DaveO Date: 22 Jul 01 - 04:26 PM Jande: Thanx. I just made that change. Dave Oesterreich |
|
Subject: RE: Virus Alert Please Read From: Peter K (Fionn) Date: 22 Jul 01 - 06:18 PM We're past 100 posts, so please go to BS: Virus Alert (continued) if you want to continue the discussion, or even if you just want to see my apology to Jeri. |
| Translate Thread |