Hi Folks, While I don't normally send out virus warnings and DO thoroughly check them out before saying anything, this one almost got me this weekend and has been received 10 times again since. Before I continue, let me tell you two things to reassure you. #1: Rootsweb lists are incapable of sending or receiving attachments and/or HTML mail, so you will not get this worm from a Rootsweb list. #2: Please note that as far as we currently know this worm only affects those using Outlook Express and Netscape Mail as their email programs, but it is a clever worm that is constantly morphing so please be aware. Now, several of you may have received mail that LOOKS like it is from a Rootsweb list that is carrying the virus, but the important thing here is that this worm is capable of "forging" it's to AND from lines so that while it is not actually coming from a Rootsweb list, it looks like it is. Rootsweb has posted information on this particular worm here: http://helpdesk.rootsweb.com/virus1.html that explains the "forging" and Symantec (the makers of Norton Antivirus) has information about the worm and how to remove it as well at http://www.symantec.com/avcenter/venc/data/worm.newapt.html Basically the best rule of thumb is NEVER open an attachment you know nothing about and if in doubt, email the "sender" to make sure that they are actually trying to send you something. ALWAYS update your virus software (i.e.. once a week is best) and ALWAYS scan any files before opening. Below is the post that was sent on to us on the listowners list by MessageMates.com. Thanks Carole for the info! Christi Visit our homepage at: http://users.idworld.net/brogan Visit our genealogy pages at: http://homepages.rootsweb.com/~cbrogan Join us for Y2KCountry! http://www.onelist.com/subscribe/y2kcountry -----Original Message----- From: Carole Rohrings [mailto:[email protected]] Sent: Saturday, December 18, 1999 11:25 AM To: [email protected] Subject: re: the virus of yesterday IMPORTANT NOTICE: We have just learned that an email worm has been found circulating the web referencing MessageMates.com. This worm file is in no way connected with MessageMates.com. If you have received an email with a message that reads: he, your lame client cant read HTML, haha. click attachment to see some stunningly HOT stuff or http://stuart.messagemates.com/index.html Hypercool Happy Year 2000 funny programs and animationsÖ. We attached our recent animation from this site in our mail! Check it out! Then you have been passed the Worm in question. It is a worm that was created and set loose by someone who ís trying to spoil all of our Holiday fun. Do not run the attachment included in the email and please delete the email message immediately! What we know about this Worm so far: 1. Symantec has named this worm: W32.NewApt.Worm. 2. Once opened/launched the worm will email itself out and reply to messages in your mailbox. 3. The file being passed as an attachment is approximately 68K. 4. The subject line of this message will vary and may appear to be a reply to something youíve previously sent. 5. The attachment is no way related to any MessageMates.com products.Ý What you can do: 1. Read the details of this worm virus by checking with Symantec at: http://www.symantec.com/avcenter/index.html 2. If you receive a suspect email with an .exe attachment from someone, first email them back and confirm that theyíve intended to send you a MessageMate. What we can tell you about MessageMates.com: 1. Our millions of loyal users are our number one priority and we are fully committed to providing software programs that are safe and fun. 2. We never send out any unsolicited emails. 3. We never send out attachments. 4. Our files are 100% safe when downloaded directly from our web site. Please know that we at MessageMates.com have worked tirelessly to earn your trust and respect. We take great pride in our products and only want our users to have a positive and entertaining experience with them. Thank you for taking the time to read this very important notice. If you have any questions or comments, please email me directly at [email protected] Chris Heitmann Chief Operating Officer Carole Rohrings [email protected]