================================================ Subject: NCR - Fw: Virus Warning from MailScan to Mail-Administrator! From: "Scott" To: Date: Fri 19 Apr 2002 08:18:48 -0400 ================================================ Look... normally this would not be a problem, and I would care less about someone here passing unknowingly being infected with a computer virus, but this is the ONLY place I have ever used my scott@creedlisters.com address... therefore, someone on this list (with the e-mail address of mmhamdy@yahoo.com) is infected with a virus, and needs to take care of it NOW. Because of this, I am suggesting that NO ONE open a mail from this person, as it is using a exploit in e-mail to download files as well as infect. DO NOT OPEN A MAIL WITH THE SUBJECT LINE "Para continuar". THIS IS THE INFECTED MAIL. The name of the virus is: File Name - 22875120.HTM Infection - "Exploit.IFrame.FileDownload" <--- this is the e-mail File Name - para.exe Infection - "I-Worm.Klez.h" <-- this is the virus If any of you know this person, inform them immediately that they are infected, and MUST get an antivirus program on their computer immediately. http://www.protectorplus.com offers a 30-day trial on a perfectly functioning personal antivirus program. http://housecall.antivirus.com offers FREE online virus scanning and removal. To anyone who feels they may have become infected with the klez virus, I am suggesting making use of this free service made available by http://www.antivirus.com. This is not a joke. Questions and comments are directed to http://www3.ca.com/solutions/collateral.asp?CT=65&ID=1705 (thanks Debbi). I suggest everyone at the very least go to this page and read about the virus... and keep your security updates and patches current (http://windowsupdate.microsoft.com). ----- Original Message ----- From: To: Sent: Friday, April 19, 2002 5:32 AM Subject: Virus Warning from MailScan to Mail-Administrator! > The attachment(s) that came with the following mail had > Viruses in it. > > ============================================================= > The Mail came from : u4ever@mail.com > The Mail recipient : scott@creedlisters.com > Subject of the Mail : Para continuar. > Message-ID : > > Attachment-Name Virus-Name Action-Taken > ------------------------------------------------------------ > 22875120.HTM "Exploit.IFrame.FileDownload" Deleted > para.exe "I-Worm.Klez.h" Deleted > ============================================================= > > Use MailScan on your EMail Servers and eScan on your > Windows-based PCs and Servers for maximum protection from > Internet-borne viruses. ----- The following addresses had permanent fatal errors ----- (reason: 554 delivery error: dd Sorry, your message to mmhamdy@yahoo.com cannot be delivered. This account is over quota. - mta614.mail.yahoo.com) ----- Transcript of session follows ----- ... while talking to mx2.mail.yahoo.com.: >>> DATA <<< 554 delivery error: dd Sorry, your message to mmhamdy@yahoo.com cannot be delivered. This account is over quota. - mta614.mail.yahoo.com 554 5.0.0 Service unavailable To unsubscribe or change your preferences for the Creed-Discuss list, visit: http://www.winduplist.com/ls/discuss/form.asp