Lyrics & Knowledge Personal Pages Record Shop Auction Links Radio & Media Kids Membership Help
The Mudcat Cafesj

Post to this Thread - Sort Descending - Home


BS: Virus Alert (continued)

Peter K (Fionn) 22 Jul 01 - 06:12 PM
Jande 22 Jul 01 - 06:28 PM
Jande 22 Jul 01 - 06:30 PM
Jeri 22 Jul 01 - 07:13 PM
hesperis 22 Jul 01 - 10:34 PM
Jeri 23 Jul 01 - 09:42 AM
dick greenhaus 23 Jul 01 - 02:35 PM
bobbi 23 Jul 01 - 05:07 PM
Jeri 23 Jul 01 - 05:38 PM
bobbi 23 Jul 01 - 07:26 PM
catspaw49 23 Jul 01 - 11:19 PM
blt 24 Jul 01 - 01:19 AM
JohnInKansas 24 Jul 01 - 05:14 AM
Mrrzy 24 Jul 01 - 11:26 AM
JohnInKansas 24 Jul 01 - 12:04 PM
MMario 24 Jul 01 - 12:10 PM
bobbi 24 Jul 01 - 01:51 PM
Jeri 24 Jul 01 - 02:40 PM
Bernard 24 Jul 01 - 04:29 PM
Bernard 24 Jul 01 - 04:39 PM
nutty 24 Jul 01 - 04:52 PM
CarolC 24 Jul 01 - 05:35 PM
Peter K (Fionn) 24 Jul 01 - 07:09 PM
Barbara 24 Jul 01 - 07:10 PM
Jeri 24 Jul 01 - 07:20 PM
bobbi 24 Jul 01 - 08:29 PM
SINSULL 25 Jul 01 - 10:09 AM
Mr Red 25 Jul 01 - 02:03 PM
Jande 25 Jul 01 - 02:15 PM
Burke 25 Jul 01 - 03:39 PM
JohnInKansas 25 Jul 01 - 04:32 PM
MMario 25 Jul 01 - 04:42 PM
dick greenhaus 25 Jul 01 - 05:23 PM
catspaw49 25 Jul 01 - 06:33 PM
Walter Corey 25 Jul 01 - 08:45 PM
alison 25 Jul 01 - 08:51 PM
Richard Bridge 26 Jul 01 - 06:44 AM
Jon Freeman 26 Jul 01 - 07:46 AM
Richard Bridge 26 Jul 01 - 07:58 AM
bill\sables 26 Jul 01 - 08:59 AM
clansfolk 26 Jul 01 - 09:07 AM
MMario 26 Jul 01 - 09:10 AM
Jon Freeman 26 Jul 01 - 09:15 AM
hesperis 26 Jul 01 - 02:00 PM
katlaughing 26 Jul 01 - 11:58 PM
catspaw49 27 Jul 01 - 12:02 AM
Allan C. 04 Aug 01 - 03:53 PM

Lyrics & Knowledge Search
DT  Forum Child
DT Lyrics:













Subject: Virus Alert (continued)
From: Peter K (Fionn)
Date: 22 Jul 01 - 06:12 PM

Please continue the Virus Alert Please Read discussion here. (For the benefit of anyone new to the forum, it's a good idea to start a new thread when the original has reached the 100-posts mark. Sometimes no-one's on hand to do the housekeeping, or can't be bothered, and a thread is allowed to go way past that number - but that can cause problems for people with slower loading computers.)

Jeri, apologies. I thought you were implying in your first post that you were safe from viruses because you stuck to plain text and didn't open attachments.

Dick, you still need to keep in mind that some viruses infect a machine, then create new emails, with or without file attachments, and send them to all the addresses listed on that machine - purportedly from the owner of that machine. Typically this will go on for two or three days before the owner of the infected machine realises that rogue messages are being generated in his or her name, by which time you could have been zapped. Nowadays, declining to open attachments may not protect you, and as I said earlier, some viruses even block any attempt to download or run anti-virus programmes.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Jande
Date: 22 Jul 01 - 06:28 PM

>From: Bill D >Date: 22-Jul-01 - 03:36 PM > >I unchecked that box a LONG time ago...I hate it when I >can't see exactly what is there. I always show >the 'detailed' view of all directories, so that all data >and settings are clear...I can hide or change anything I >want IF it ever seems temporarily useful to do so....

Same here! And just to make sure... my message was for those users who are not experienced users (sometimes called "power" users --probably because we don't like to be put in positions of powerlessness by folks like B.Gates, et al.) :`)

Thanks very much for the alert, Bill.

~ Jande


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Jande
Date: 22 Jul 01 - 06:30 PM

DaveO: "Thanx. I just made that change."

You're welcome! Glad to be able to be of some help on this. :`)

~ Jande


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Jeri
Date: 22 Jul 01 - 07:13 PM

Fionn, no apology needed. If you thought I was implying any message without an attachment is safe, other people might have as well. It's best to bring it up and get to the truth. (And I'm fully aware that I can be confusing at times!)

Sircam needs to hide in an attachment, other worms don't.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: hesperis
Date: 22 Jul 01 - 10:34 PM

Jande, would you help CarolC with her computer's colour problem? Either she has a virus, or windows is in safe mode and won't get out of it. What button do you press while booting up to get the menu, again? Was it F1? F2? F8?


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Jeri
Date: 23 Jul 01 - 09:42 AM

Fionn, I just re-read your message with a few more brain cells operating.

You said "I thought you were implying in your first post that you were safe from viruses because you stuck to plain text and didn't open attachments."

In the previous thread, you said "There are one or two misunderstandings floating around in this thread. In particular, Jeri, you need to know that there are viruses around now that do NOT require file attachments to be opened. One such that is rampant at present is known as MTX.9244. This proliferates as a trojan and a worm. The trojan element manifests itself as an incoming email with no subject, no message and a file attachment that is gobbledegook and can't be opened. It arrives simultaneously with a genuine email from someone already (and usually unknowingly) infested, and claims to be from that same person."

I found info on the MTX virus at F-Secure and Symantec. It seems like it spreads by attachment, and you have to attempt to open it to be infected.

Anyway, what I think you were saying is that I can be infected through e-mail simply by receiving and viewing a message in plain text, or by receiving an attachment without attempting to open it.

I can't find anything that says this is possible, and I've looked. Is this what you meant? Could you explain further. (Please PM me if you'd rather.)

The way I understand viruses and worms, you need do do something to 'activate' them. This can be done by trying to open an attachment, or by using a browser that interprets HTML and any script within it.

I'm not arguing here, just trying to understand. (I used to drive the systems guys at work 'buggy' with questions, but my questions and their patient answers made me a lot less ignorant.)


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: dick greenhaus
Date: 23 Jul 01 - 02:35 PM

I can only point out, in a curmudgeonly way, that this kind of crap didn't occur with older operating systems.

And I can't see how a plain text message can contain a virus. Could someone explain?


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: bobbi
Date: 23 Jul 01 - 05:07 PM

In order to get a virii/worm, there has to be an attachment and the attachment has to be executable, ie., exe.. Once you click on the attachment to open it.. whether or not you think you did (many are masked to indicate they can't be opened), it is opened and down loading to your hard drive. If you do not attempt to open the executable file and just delete it, you are safe from that particular infected e-mail. You can not get a virii from a plain text e-mail, but can from an e-mail containing an exe. pain text file. Make sense? You have to execute an action in oder to get a virii... simply opening an e-mail won't do it.. It has to have an exe. file attached and you have to click on it. Attachments in e-mails like mpeg abd jpeg are not exe. programs and are safe. So if you just avoid opening exe. files or any other down loads, a virii can not down load to your hard drive and infect your PC. I have a webtv that I use for the internet as it CAN NOT be infected with a virus.. the reason? It can not open executable files... Hope this helps.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Jeri
Date: 23 Jul 01 - 05:38 PM

Except if you use a browser that uses HTML with scripting enabled. (I'm thinking about the Kak worm, but there are others.) There are no attachments. You open the e-mail and the embedded script does its thing.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: bobbi
Date: 23 Jul 01 - 07:26 PM

I have a browser that uses HTML and scripting is enabled... I will investigate the Kak virii, but don't think so... If you do not run a prgram, it would quite impossible to take on a worm to your hard drive. That would be like saying, if you view any script on the internet that was infected then you would be also. How can just viewing something with a virii, jump onto your PC hard drive? If it's not down loaded then it can not get into your hardware.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: catspaw49
Date: 23 Jul 01 - 11:19 PM

Here's an interesting piece........CLICK

Spaw


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: blt
Date: 24 Jul 01 - 01:19 AM

I want to thank everybody who took the time to give detailed information on how to disable this virus. I got it a few days ago, went to the first site Jeri listed and clicked where I was told to click, but then I couldn't find any file listed under the names described. Then I lost contact with Mudcat (the Windows error message, and I never understood what I was supposed to do about that, other than wait) until tonight. I went back to the first part of this thread and re-read it, came upon a posting that listed alternate titles for the worm, started trying them and caught the sucker, deleting it with relish. It felt like I was in the Matrix, vaccuuming that thing out of Keanu Reaves navel...

One interesting note--I have Outlook Express on my computer (a Gateway), but I switched to Netscape when I moved to Oregon. However, my OE address book is still in place and that seems to be what the worm latched onto. However, it latched onto the address for Cheshire Net in Keene, NH (where I used to live)and luckily some techical guy recognized it as a probable virus. Other than that, I haven't been notified of any problems, although they might be out there since I didn't fully get rid of the worm until about 10 minutes ago. I also went to the Symantec site to check out the Norton ware--will it cause problems to download Norton's stuff if I already have McAfee? Do I have to take the McAfee program off first or do I just stop using it?

blt


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: JohnInKansas
Date: 24 Jul 01 - 05:14 AM

Food for thought:
Many of us are familiar with JC's tunebook, but may not have explored his whole site. If you go to his home page, JC's home< he has an interesting little display that might be called "watch the bouncing balls." There is a clicky on the site to give you way more than you want to know about the little balls, but (sadly, but probably appropriately) not much about the remedies. You may or may not be able to see the balls, but anyone should be able to get to his comments.

Frankly, I get a sorta queasy feelin' whenever things move, on websites but especially in email. The problem is, that the more these little devices get used, the easier it is for some A... to hide something malicious in one of them.

John


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Mrrzy
Date: 24 Jul 01 - 11:26 AM

Was it because of the virus that I haven't been able to access Mudcat since Friday?


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: JohnInKansas
Date: 24 Jul 01 - 12:04 PM

Mrrzy:

The access problem was discussed in this thread:
NT Error

Of course, if everybody finds out about this, the traffic on the UP servers may make them all DOWN.

John


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: MMario
Date: 24 Jul 01 - 12:10 PM

the KAK and some others are not virii - but rather script-worms. The default for some MS mail programs is to have scripting enabled and automatic. Thus when the attachment comes in - the script runs and the worm burrows in.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: bobbi
Date: 24 Jul 01 - 01:51 PM

About the VBS.KAKWorm The Wscript KAK Worm is a worm/virus that attacks systems using Outlook Express. It uses a known security vulnerability to attach itself to every email sent from an infected system. It is written with Javascript and it attacks both the English and French versions of Windows 95/98, if Outlook Express 5 is installed. Then what makes this worm unique is its ability to infect a system by someone simply reading or previewing an email message. The worm hides in the HTML of the email itself. When the message is previewed or opened by the recipient, the worm automatically takes control and infects the computer. If neither Outlook Express nor MS Internet Explorer 5.0 are installed, the worm is not able to infect the machine. The worm has another potential side effect as well. On the 1st day of any month and the hour is 5:00pm, the following message is displayed and Windows is sent a command to shutdown. You may also see a "Driver Memory Error" occur when starting Windows. What The Worm Does Upon infection, the worm places a file called KAK.HTM in your C:\Windows directory and a temporary file with an .HTA extension in your C:\Windows \SYSTEM directory. It also places a file called KAK.HTA in your Startup directory. Then the worm adds the following lines into your AUTOEXEC.BAT file and renames the original autoexec file to AE.KAK. @echo off>C:\Windows\STARTM~1\Programs\StartUp\kak.hta del C:\Windows\STARTM~1\Programs\StartUp\kak.hta Next the worm adds the following changes into the Windows Registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows \Currentversion\Run\cAg0u This cAg0u file points to the temporary .HTA file dropped into the Windows\System directory earlier. The worm also adds the following line into the Windows Registry. HKEY_CURRENT_USER\Identities\Software\Microsoft\Outlook Express\5.0\signatures\Default Signature This default signature points to the KAK.HTM file loaded into the Windows directory. Every email that is sent after infection has this KAK.HTM embedded in the HTML of the email which spreads the worm to others.

But again: You MUST have Outlook Express and MS Internet Explorer 5.0 installed... So in that regard, yes it is possible to get a virii/worm via script, but all these other factors must be in place as well.  


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Jeri
Date: 24 Jul 01 - 02:40 PM

Amusing anecdote: I don't have Outlook or Outlook express. I (as I mentioned) use a text browser, so if someone sends me a message in HTML, it looks goofy. Normally, I just ignore HTML e-mail messages, but I was curious about what all that stuff would look like.

I copied and pasted it into Notepad and saved it as HTML, then I opened it. I infected my computer. Now, I couldn't send it without Outlook, but it still would have done all the damage to my hard drive it would have if I'd had Outlook.

Granted, infecting my computer took a level of stupidity not ordinarly found in the general population, but all I did was to open an HTML document with scripting enabled. This did scare the hell out of me because it meant that if someone put the worm on a web page and I didn't have an up-to-date anti-virus program, I was hosed. (I don't think it's likely this would happen as it would be too easy to find and prosecute the offender.) Outlook DOES use HTML to read and write messages, but are there others?

Just to be pedantic, according to one of those anti-virus sites, the plural of 'virus' as used in English is 'viruses.' There is no plural in Latin. 'Virus' is a mass noun such as 'air'.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Bernard
Date: 24 Jul 01 - 04:29 PM

As in 'airs and graces'?!!

;o)


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Bernard
Date: 24 Jul 01 - 04:39 PM

On a more serious note - supposing someone without anti-virus software inadvertently uploaded an infected script onto their website...

I didn't have any AV sofware active on my computer until very recently, but I've had a spate of infected emails.

Luck has been on my side, because they were all of the attachment type, and I didn't get infected (nor did my computer!).

For the past month I've been running Norton Antivirus, because my luck could run out...


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: nutty
Date: 24 Jul 01 - 04:52 PM

Jeri .... I seem to remember reading in a magazine that this is a problem with Outlook Express that Microsoft are aware of and a patch is available at their web-site.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: CarolC
Date: 24 Jul 01 - 05:35 PM

I just talked to the guy who worked on my computer. He told me not to use the Norton Internet Security, but to just use the Norton Anti-Virus instead. He's going to have to re-install one of my drivers (the one that will let me have more than 12 colors). He said the Internet Security system is responsible for the problem.

I'm probably going to return the Security System and just buy the Anti-Virus software, but Norton makes returning products pretty complicated. I'm not very happy with Norton right now.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Peter K (Fionn)
Date: 24 Jul 01 - 07:09 PM

Good post (your last one) Bobbi, and I think it covers to point that Jeri put to me. But you are right to feel fairly safe, Jeri, given that you operate such a remorselessly Spartan regime!

Bernard, one of the points to have emerged in this thread is that no anti-virus software guarantees to keep you safe from everything. McAfee and Norton obviously lead the way, but there are some worms that will be best sorted by Command. Even now, iterations of worms and viruses are being produced that will get past everything presently on the market. That's why new patches are constantly being written for all anti-virus software packages. It's an endless game of leapfrog.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Barbara
Date: 24 Jul 01 - 07:10 PM

I missed the first couple rounds of sircam from Dick and Alison and Bill (Did get an email from Bill, but not an attachment), but somebody finally caught me yesterday. Do we have a a.b. on list somewhere? Someone who uses eazenet?
Anyway, Norton Anti-Virus got it and quarantined it for me, and now I've got a really lame question. Can I just delete the attachment from the quarantine folder? (The bl**dy program tells that to delete it will take it out of the folder; but it doesn't say what happens then -- does deleting kill the virus?) Sorry if this is a "duh", I'm just never sure if software is doing what I think it is.
Blessings,
Barbara


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Jeri
Date: 24 Jul 01 - 07:20 PM

Barbara, deleting the worm will only cause problems if you're infected. If Norton stopped that happening, deleting it shouldn't cause any problems.

Fionn, thanks. Yeah, it's spartan, but I never saw the need for the fancy stuff. (Hey, at least I have electricity here!)


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: bobbi
Date: 24 Jul 01 - 08:29 PM

Sorry Jeri.. I should have explained.. Virii is a word that "We In The Know" use in the computer lab to describe any virus or worm. Pardon, if I confused you. I am amazed that you contracted the KAK worm and do not have Outlook Express 5 or Explorer 5.0.. so is everyone else in the lab.. Perhaps there is something new going on that we don't know about yet. That's scary!


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: SINSULL
Date: 25 Jul 01 - 10:09 AM

A Tale Of What Not To Do:

Shark Tank: It's baaaaaack ...

An e-mail virus -- the kind that uses Microsoft Outlook to replicate itself -- slips past a state agency's antivirus software one Friday.

But a vigilant sysadmin pilot fish spots it in his in-box. The virus has already sent itself five times to everyone in the global address list.

Fish immediately broadcasts a high-priority, all-staff message warning everyone that the message contains a virus and instructing them to delete it without reading it.

Suddenly, the trickle of infected e-mail turns into a flood, and the fish has to take the mail server down to stop the virus's spread.

Fish tracks down one of the last users to open the virus-laden message. Why did you open it? he asks. Didn't you see my message?

Replies the user, "The message must have contained something good if management didn't want us to read it."

Fish spends the weekend running a utility to move all infected messages to the Deleted Items folder.

Monday morning, the virus flood starts again -- and again fish takes the mail server off-line.

How did you get the virus again? fish asks one culprit.

"I undeleted the message from the Deleted Items folder," user tells fish. "I hadn't read the message yet."

Fish spends a grim day and night moving all infected messages to the Deleted Items folder -- and emptying everyone's Deleted Items folder.

Tuesday, the flood renews itself a third time.

Where did you get it? exasperated fish asks the first user who opened the infected message.

"I used the Recover Deleted Items feature to undelete it," user chirps. "I was using it to recover another message, but when I saw that message, I remembered reading an all-staff about it.

"So I opened it to see what all the fuss was about."

_____________________________________________________________

Experience Real Life in IT

Each weekday Computerworld's Daily Shark brings you the rumors, scoops, gossip, humor, and anguish of real life in IT. To subscribe go to:

http://www.cwrld.com/nl/sub.asp

Remember, Computerworld's E-mail Newsletters are free, there's no obligation, and you can switch among topics or unsubscribe at any time. Check us out and sign up now!


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Mr Red
Date: 25 Jul 01 - 02:03 PM

OK, so when I find-out how I turn-off the scripting in OE5 I do it.
but did we get a re-iteration of a warning on other executables like .COM and .BAT files? And obviously .HTM files. (.html and .shtml likewise)
Sorry if I repeat but I heard that some viruses come in on files with names like openme.txt.exe on the premise that some folks have turned off their extension visibility and don't realise that what looks like openme.txt is in fact an exe file. Surely this refers to Explorer not the e-mail app, but a clever script could save the file for you. I always have the extensions visible.

I had an e-mail recently from someone I know not. Subject line was !"#$ (shift 1234 on any American keyboard - not on UK) no message and an attachment called NOTEPADE.EXE. Immediate delete and no repercussions. More I can not tell you as I didn't hang about for the diagnosis nor analysis.

don't cgi files contain a bit of cleverness? Isn't PERL a scripting language?


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Jande
Date: 25 Jul 01 - 02:15 PM

CarolC: Just saw the note from Hes about your computer trouble, then your note that it was norton Internet security that screwed things up for you.

Glad you found a helpful Solution. Congratulations!

We've got Norton Systemworks 2001. All I ever install from it is NAV, Speeddisk (MUCH better than Windoze Defrag), and the LIveUpdate. It installed extra stuff than what I asked it to but I uninstalled all that.

Man, I *hate* push-technology! :`)

~ Jande


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Burke
Date: 25 Jul 01 - 03:39 PM

I am so glad I heard about it first here before having a problem!

I was feeling a bit left out on all this, but had warned people I work with not to open attachments because of this spreading plague.

Yesterday we received notice from out ITS dept. at noon to restart our computers & automatically download the new virus definitions for SOPHOS. No virus on my machine a suspected.

Today I got it in an e-mail from someone I've never heard of. Is it true that OE automatically adds anyone you've received mail from to your address book? I heard this somewhere & since I'm active on a couple of mailing lists I could end up in all kind of strangers' address lists.

People who use Compuserve's e-mail program cannot turn the html off. I have some friends for whom this is causing general problems. Did someone say they don't have to use Compuserve's program? Where can I send them for guidance in how to configure Eudora to work with their Compuserve account?


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: JohnInKansas
Date: 25 Jul 01 - 04:32 PM

I've just returned from another session on the MickeySoft Knowledge Base (non-sequitor?) and while I was there trying to solve some other things, I tried to take a look at whether I have the latest "security updates" for all of my stuff.
As usual, after a session like this, I'm pretty thoroughly confused - I've chawed and swallered, but the digestin' ain't set in.
I think(?) they are trying to tell me that people using Internet Explorer 5.5 (and possibly later) probably need at least one "Service Pack" installed to have the current best security features.
I can't use IE5.5 without giving up a good existing email program, since it doesn't support the protocol used, so I'm stuck with an IE5.0x.
There appears to be "latest and best" "Service Pack 1 for IE5.01" that does everything they have to offer at the present. It appears(?) that IE5.5 already incorporates most of the features that this SP adds to earlier versions. BURP?(digesting)
It also appears that the IE5.01 SP1 can be added to IE5.0 to get the same result, but don't quote me on that yet.
I'm not sure that I'm reading everything right at present, but they seem to say that (with IE5.01 SP1 or better) if the "Security Level" in IE properties is set to "Highest," then "Active Scripting" is automatically turned off. This would seem to be a good thing, but I'm not sure what that high a security setting would do to being able to make connections.

A question for those more knowledgeable...How essential is it to turn off html if active scripting is disabled?
And, of course, I still have to do the same search for OutlookExpress.
And there's the question of why they're calling it MSN Explorer now instead of Internet Explorer. Two different programs, or just two different salesmen?

Confused
John


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: MMario
Date: 25 Jul 01 - 04:42 PM

burke - the default of OE is to add sender of each e-mail to your address book if they are not already there. it can be turned off.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: dick greenhaus
Date: 25 Jul 01 - 05:23 PM

Well, I usw neither Outlook Express nor Explorer. I still got it.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: catspaw49
Date: 25 Jul 01 - 06:33 PM

Just got the following from my ISP.....

Hello,

We are writing to inform you that on 17 Jul 01, we successfully blocked a very nasty virus from being sent to entering our email server and being sent to our users. You can read more datails about it here: http://www.symantec.com/avcenter/venc/data/w32.sir cam.worm@mm.html If you think you have this virus please contact us.

Our Systems Administrator John and one of our Technicians John Paul came in at 2AM to place a filter to block this nast virus for you.

If you are in need of computer repair or upgrades please let us know, we are here to serve you!

BuckeyeNet


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Walter Corey
Date: 25 Jul 01 - 08:45 PM

I've been using OE for my ISP based e-mail, since that's the only option they gave me. After reading all this, I may just go back to web-based mail and ditch OE. I'd gotten pretty sick of all the spam on hotmail, but I notice that now they give you a bunch of different options, including just delivering mail to the inbox from people on your address list. Of course you have to keep a close watch on the junk mail folder and make sure your address book is up to date. Before I go that route, does anybody know if it is possible to set OE so that it just reads plain text, and not HTML and embedded scripts? All I can find along that line is for the sending mode, not the reading mode.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: alison
Date: 25 Jul 01 - 08:51 PM

I got another one today from California, so it is still going around....

slainte

alison


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Richard Bridge
Date: 26 Jul 01 - 06:44 AM

I can't get back to the previous thread, and someone just sent me the original virus the subject of this thread. Outlook says it blocked the attachemnt and Norton says no viruses found (definition date 18July2001) but I wanted to check the name of the virus and visit the fix site just to make sre.

Can someone fix the link?

The mirror sites seem to have the same or a similar problem


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Jon Freeman
Date: 26 Jul 01 - 07:46 AM

Just read the thread and as I still have an edit key, I have "fixed" the link. There are 2 ways of giving the URL, absolute, e.g. http://www.mudcat.org/thread.cfm?threadID=12345 or relative, e.g /thread.cfm? threadID=12345.

Could I suggest that people try to give relative links to other threads in Mudcat. The advantage is, the full URL is based on the server/mirror a user is on, e.g. if Loki is the only mirror running, the link will still work.

Jon


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Richard Bridge
Date: 26 Jul 01 - 07:58 AM

Thanks Jon.

I just tested with a mate of mine at BT (British Telecom, for those from across the pond) and he confirms no virus associated with my email so it seems the security settings in Outlook or my Norton stopped and/or cleaned the virus (Sircam) before any harm done. I didn't get sent it by anyone from mudcat, but by a hi-tech client!

He is the only PC user in the organisation. All the creatives use MACs, so there is a slightly cavalier attitude (us and them) to virii there. Once bitten....


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: bill\sables
Date: 26 Jul 01 - 08:59 AM

I am now completley clear of the virus thanks to Jon Freeman who come up to my home and sorted it all out for me, Thanks Jon
Bill


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: clansfolk
Date: 26 Jul 01 - 09:07 AM

A very large download today took 8 minutes - only one email - in Spanish? with attachment - guess what and where it's gone - Nortons spotted it again. They also transmitted a warning on the local radio re the Virus.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: MMario
Date: 26 Jul 01 - 09:10 AM

richard - the newer mailworms and some trojans CAN operate on Macs that use MS products. 'course I know that that is almost as distasteful as using a PC so you should be safe.


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Jon Freeman
Date: 26 Jul 01 - 09:15 AM

Don't mention Norton!

When I was with Bill yesterday, he (wisely IMO) decided to purchase Norton Antivirus and Firewall which he bought on line as a download from the Symantec site.

The download was 30Mb and it crashed the first time about 2 1/2 hrs - near the end so we had to start again - 5+ hrs just to get the software.

Anyway, it installed OK and hopefully all is well with Bill's computer. I hate doing what I did last night but I didn't really check things were working as thoroughly as I'd usually do - just ran out of time (at least if we were going to get to a session and meet my mother there).

I haven't read all of this thread or the previous thread so I may be repeating something here. The symantec site that someone gave a link to now has a downloadable program to remove Sircam. It proved useful yesterday.

Jon


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: hesperis
Date: 26 Jul 01 - 02:00 PM

Haven't got it yet, but I use Pegasus for my personal email, and have plain-text only set as default... I also set it up so it asks if I want to see attachments. Some emails come in with no text equivalent, and I get to choose if I want to see it.

I always send plain text, too. I hate html email, half the time when you try to reply to it, it doesn't quote correctly, especially when using hotmail. Grah!

As for configuring your email reader - my ISP gave me a booklet with the install, that has all the user information and mail server addresses, etc, at the back of the booklet. If you read the readme file for the email program you choose, there should be no problem setting up. And your ISP should give you the information you need if you ask. Actually, if you explore the program you are using (without changing anything!) you should be able to find out what mail server you are supposed to use.

You need to know your user name, mail password, outgoing mail server, and incoming mail server.

Then just plug those values in where the program asks for them. Leave almost everything else at the default values, and read the help files and the readme.

Hope that helps.

~*hesperis*~


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: katlaughing
Date: 26 Jul 01 - 11:58 PM

I just received an email from a Mudcatter which had "GREEN" in the subject line and that was the only word in the text, also. There was an attachment, which I did not open, which was called "CPQStart.z(the number one or a lower case ell)9"

I contacted the sender and he did not send it to me. I've deleted it. Nothing by that name showed up at Symantec.

Anyone have any idea what kind of file it might have been, virus or not?

Thanks.

kat


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: catspaw49
Date: 27 Jul 01 - 12:02 AM

Hi kat......See this thread.

Spaw


Post - Top - Home - Translate

Subject: RE: BS: Virus Alert (continued)
From: Allan C.
Date: 04 Aug 01 - 03:53 PM

Well, folks, Big Mick just got back from a long absence to discover that his computer has also been infected. I just got an infected message from his computer. No harm done, though, because I know the drill. Mick has shut down the magic box until he can get things straightend out. I am just making note here of his problem so that you guys will watch for a suspicious-looking message - with attachment that will appear to be from him.


Post - Top - Home - Translate


 


This Thread Is Closed.


Mudcat time: 28 July 4:48 AM EDT

[ Home ]

All original material is copyright © 2022 by the Mudcat Café Music Foundation. All photos, music, images, etc. are copyright © by their rightful owners. Every effort is taken to attribute appropriate copyright to images, content, music, etc. We are not a copyright resource.