Note: The Rootsweb Mailing Lists will be shut down on April 6, 2023. (More info)
RootsWeb.com Mailing Lists
Total: 1/1
    1. Re: [GREEN] One of you has a VIRUS! I am holding it on my PC in quarantine
    2. George Greene
    3. Dear GREEN List, I'm also on several other lists, and have been getting warnings like this from those listings all day, and in each one the File name mentioned the word "HAMSTER", or "DOC". I will do a cut and paste of a couple of warnings that I have received today, in the hopes that they will help someone else. (Please note that the words 'HAMSTER' and 'DOC' appear in the first warning), ~ Etta POST # 1). If you receive a message with an attachment and the message body is blank DO NOT OPEN IT!!! Description: W32/Badtrans-B is a worm which uses MAPI to spread. The worm arrives in an email message with no message text. The attachment filename is randomly generated from three parts. The first part is taken from the list: FUN HUMOR DOCS S3MSONG Sorry_about_yesterday ME_NUDE CARD SETUP SEARCHURL YOU_ARE_FAT! HAMSTER NEWS_DOC New_Napster_Site README IMAGES PICS The second from the list: .DOC. .MP3. .ZIP. and the last from: pif scr If the attached file is run, it copies itself into the Windows system directory with the filename KERNEL32.EXE and changes the registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce so that the worm runs the next time Windows is started. The worm also drops a file named kdll.dll, which is the password stealing Trojan Troj/PWS-AV. If you suspect you have received a virus from a subscriber to this list please email [email protected] with details. POST # 2). We haven't had an informational post in quite a while (a regular stationery post will follow in a few minutes). Since my anti-virus program has caught over 20 emails containing worms/viruses in the past 2 days, I thought it was time. :) A new worm hit the web Nov. 24.....W32.Badtrans.B @mm......this is different than the other Badtrans worm and obviously it is spreading fast! Please make sure you update your anti-virus programs immediately!! For more info and how to remove this worm go here and click on the name of the worm. http://securityresponse.symantec.com/ If you don't have an AV program, please consider installing one. Below are some websites for pay and free ones. http://www.symantec.com/avcenter/vinfodb.html http://www.antivirus.com/pc-cillin/vinfo/ http://vil.mcafee.com/ www.grisoft.com AVG Anti-Virus (free) http://antivirus.cai.com/ InoculateIT Go ahead and "blast it", Mellie! Good Luck! Etta ----- Original Message ----- From: "Mellie" <[email protected]> To: <[email protected]> Sent: Monday, November 26, 2001 3:10 PM Subject: [GREEN] One of you has a VIRUS! I am holding it on my PC in quarantine > for the time being, I have received an email with an attachment from > Elizabeth -Angela Guyver, re: Shadrack green > I have not opened it but media placyer started for reasons best know > to its self, my AV will hold in quarantine, can Elizabeth confirm via > list (as rootsweb will prevent the virus from getting through)that she > did or did not send email to me with an attachment before I blast it > to kingdom come! > Mellie > IBSSG > Diagonally parked in a parallel universe > > > --- > Outgoing mail is certified Virus Free. > Checked by AVG anti-virus system (http://www.grisoft.com). > Version: 6.0.298 / Virus Database: 161 - Release Date: 13/11/01 >

    11/26/2001 01:31:29