================================================ Subject: Re: NCR - Fw: Virus Warning from MailScan to Mail-Administrator! From: "Debbi" To: Date: Fri 19 Apr 2002 09:15:50 -0700 ================================================ You should know that this virus changes the text of the body and the text of the subject line each time it sends a copy, so Scott, the text that you get on the subject line won't be the text on another person's virus laden mail. Also remember that researchers don't always know what, if any backdoors are put onto the machine by viruses. If you really want to be sure you're not infected and vulnerable to future attacks, wipe the machine and all the files in it. One other thing. Windowsupdate.microsoft.com doesn't always have the patches ready as fast as the security site: http://www.microsoft.com/technet/security If only people would patch their machines and learn a bit about netiquette. Oh wait. We've been thru that. debbi -----Original Message----- From: Creed Discussion List [mailto:CREED-DISCUSS@WINDUPLIST.COM] On Behalf Of Scott Sent: Friday, April 19, 2002 5:19 AM To: CREED-DISCUSS@WINDUPLIST.COM Subject: NCR - Fw: Virus Warning from MailScan to Mail-Administrator! Look... normally this would not be a problem, and I would care less about someone here passing unknowingly being infected with a computer virus, but this is the ONLY place I have ever used my scott@creedlisters.com address... therefore, someone on this list (with the e-mail address of mmhamdy@yahoo.com) is infected with a virus, and needs to take care of it NOW. Because of this, I am suggesting that NO ONE open a mail from this person, as it is using a exploit in e-mail to download files as well as infect. DO NOT OPEN A MAIL WITH THE SUBJECT LINE "Para continuar". THIS IS THE INFECTED MAIL. The name of the virus is: File Name - 22875120.HTM Infection - "Exploit.IFrame.FileDownload" <--- this is the e-mail File Name - para.exe Infection - "I-Worm.Klez.h" <-- this is the virus If any of you know this person, inform them immediately that they are infected, and MUST get an antivirus program on their computer immediately. http://www.protectorplus.com offers a 30-day trial on a perfectly functioning personal antivirus program. http://housecall.antivirus.com offers FREE online virus scanning and removal. To anyone who feels they may have become infected with the klez virus, I am suggesting making use of this free service made available by http://www.antivirus.com. This is not a joke. Questions and comments are directed to http://www3.ca.com/solutions/collateral.asp?CT=65&ID=1705 (thanks Debbi). I suggest everyone at the very least go to this page and read about the virus... and keep your security updates and patches current (http://windowsupdate.microsoft.com). To unsubscribe or change your preferences for the Creed-Discuss list, visit: http://www.winduplist.com/ls/discuss/form.asp