Note: The Rootsweb Mailing Lists will be shut down on April 6, 2023. (More info)
RootsWeb.com Mailing Lists
Total: 1/1
    1. [KYLEWIS-L] [Fwd: Fw: [SUTTON-L] CIH virus Aimed at Windows 95, 98 users only]
    2. Derre Maybury
    3. This is a multi-part message in MIME format. --------------2A2D51736D Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Thought you would like to read this! --------------2A2D51736D Content-Type: message/rfc822 Content-Transfer-Encoding: 7bit Content-Disposition: inline Return-Path: <[email protected]> Received: from cdale3.midwest.net ([208.235.1.20]) by sv10.batelco.com.bh (Post.Office MTA v3.5.3 release 223 ID# 589-54461U20000L20000S0V35) with ESMTP id bh for <[email protected]>; Sat, 24 Apr 1999 16:37:11 +0300 Received: from ronda (carrollton25.midwest.net [208.235.22.163]) by cdale3.midwest.net (8.9.3/8.9.1) with SMTP id IAA05850; Sat, 24 Apr 1999 08:33:59 -0500 (CDT) Message-ID: <[email protected]> Reply-To: "Marty Crull" <[email protected]> From: "Marty Crull" <[email protected]> To: "Tunie" <[email protected]>, "Barb Stramel" <[email protected]>, "Ron & Joann" <[email protected]>, "Roberta" <[email protected]>, "Rhonda Jo" <[email protected]>, "Russ and Janice Pullen" <[email protected]>, "Derre Southworth Maybury" <[email protected]>, "Mary(Webpage)" <[email protected]>, "nevada lay" <[email protected]>, "Donna E. Kilroy" <[email protected]>, "Kathy Mae" <[email protected]>, <[email protected]>, "Jayne" <[email protected]>, "Gary Crull" <[email protected]>, "Edith" <[email protected]>, "Denny" <[email protected]>, "Cindy" <[email protected]>, "Byland, Steve" <[email protected]>, "Jean Bushnell" <[email protected]>, "Phyllis Brefeld" <[email protected]>, "Bonnie" <[email protected]>, "Bob French" <[email protected]>, "Big Al" <[email protected]>, "Phyllis Bauer" <[email protected]> Subject: Fw: [SUTTON-L] CIH virus Aimed at Windows 95, 98 users only Date: Sat, 24 Apr 1999 08:34:16 -0000 MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 4.72.3110.1 X-MimeOLE: Produced By Microsoft MimeOLE V4.72.3110.3 Content-Transfer-Encoding: quoted-printable X-MIME-Autoconverted: from 8bit to quoted-printable by cdale3.midwest.net id IAA05850 X-Mozilla-Status: 0001 Please read the attached url. Looks like a bad one. -----Original Message----- From: C. VanV <[email protected]> To: Martin Leon Crull <[email protected]> Date: Friday, April 23, 1999 9:47 PM Subject: Fw: [SUTTON-L] CIH virus Aimed at Windows 95, 98 users only >Marty, Here it is. It has some info and then pages to look at. Carol >-----Original Message----- >From: Milo Sutton <[email protected]> >To: [email protected] <[email protected]> >Date: Friday, April 23, 1999 2:38 PM >Subject: [SUTTON-L] CIH virus Aimed at Windows 95, 98 users only > > > >>From Milo Sutton, Sutton List Owner: > >The latest authentic virus warning comes from Wired Magazine's web site: > > http://www.wired.com/news/news/technology/story/19280.html > >In part, it reports:"The havoc caused by the Melissa computer virus is t= ame >compared with the destruction expected to strike on 26 April. > >"The CIH virus is believed to be the first virus to attack a PC's BIOS >(basic input/output system), the built-in program that helps a machine >boot. The virus can overwrite hard drives, and because it has a long >incubation period it is now believed to be widely distributed." (Go to t= he >above URL for additional information. > > And . . . > >The below techical description of the new, deadly virus aimed at _only_ >users of Windows 95 and Windows 98 is reprinted from > >http://www.cert.org/incident_notes/IN-99-03.html > > CERT=AE Incident Note IN-99-03 > > The CERT Coordination Center publishes incident note= s >to provide information about incidents to the Internet community. > > CIH/Chernobyl Virus > > Thursday, April 22, 1999 > Friday, April 23, 1999 -- Updated vendor information > > Overview > > We have received a number of information requests about a >computer virus named CIH. Anti-virus vendors hav given this virus the >following names: CIH, Win95.CIH, PE_CIH, Win32.CIH, and W95/CIH.1003. Th= e >virus has also been called the Chernobyl virus. Some versions of the CIH >virus become active on April 26, 1999 which is the 13th anniversary of t= he >Chernobyl disaster. > > Description > >The CIH virus infects executable files and is spread by executing an >infected file. Since many files are executed during normal use of a >computer, the CIH virus can infect many files quickly. > >There are several variants of the CIH virus. Some activate every month o= n >the 26th, while other variants activate just on April 26th or June 26th. >Once the CIH virus activates, the virus attempts to erase the entire har= d >drive and to overwrite the system BIOS. Some machines may require a new >BIOS chip to recover if overwritten by the CIH virus. CIH only affects >Win95/98 machines. > >More technical details about the CIH virus can be found at the following >site. > > http://www.virusbtn.com/VirusInformation/cih.html > > Solutions > > Many motherboards have a "jumper" that will enable or disable the >ability to write to the BIOS. To prevent the CIH virus or any other prog= ram >from writing to your computer BIOS, we recommend that you set the >motherboard jumpers so that the BIOS can not be modified. Some motherboa= rds >vendors may ship with the jumper set in the writable/programmable mode f= or >the BIOS. > >This is a known virus and anti-virus vendors are able to detect the CIH >virus. To detect and remove current viruses, you must update your scanni= ng >tools and anti-virus software with the latest virus signatures or >definitions. To properly clean the CIH virus we recommend booting an >infected computer from a clean floppy diskette (one that is not infected= ) >and then run anti-virus software. > > Vendor Information > > Below is a list of anti-virus vendors that have futher infomation >and tools relating to the CIH virus. > > Computer Associates InoculateIT > http://www.cai.com/virusinfo/melissa_virus.htm#cih > > Current Virus Signature Versions that Detect and Cure the CI= H >virus are as follows: > Any version of InoculateIT signature file later than 4.15 w= ill >detect and cure CIH. > Current version of InoculateIT signature file is 4.20. > > Any of the above virus signatures files can be downloaded at >www.support.cai.com > > Network Associates/McAfee > >http://www.avertlabs.com/public/datafiles/valerts/vinfo/spacefiller411.a= sp > > ProLand Software > http://www.pspl.com/faqs/cihfaq.htm > http://www.pspl.com/download/cleancih.htm > > Sophos > >http://www.sophos.de/companyinfo/pressrel/uk/19990310chernobyl.html > > Symantec/Norton AntiVirus > http://www.symantec.com/avcenter/venc/data/cih.html > http://www.symantec.com/avcenter/kill_cih.html > > TrendMicro > >http://216.33.21.51/vinfo/virusencyclo/default3.asp?VCode=3DEN001344 > > This document is available from: >http://www.cert.org/incident_notes/IN-99-03.html. > > > CERT/CC Contact Information > > Email: [email protected] > Phone: +1 412-268-7090 (24-hour hotline) > Fax: +1 412-268-6989 > Postal address: > CERT Coordination Center > Software Engineering Institute > Carnegie Mellon University > Pittsburgh PA 15213-3890 > U.S.A. > >CERT personnel answer the hotline 08:00-20:00 EST(GMT-5) / EDT(GMT-4) >Monday through Friday; they are on call for emergencies during other hou= rs, >on U.S. holidays, and on weekends. > > Using encryption > > We strongly urge you to encrypt sensitive information sent by ema= il. >Our public PGP key is available from > http://www.cert.org/CERT_PGP.key. If you prefer to use DES, pleas= e >call the CERT hotline for more information. > > Getting security information > > CERT publications and other security information are available fr= om >our web site http://www.cert.org/. > > To be added to our mailing list for advisories and bulletins, sen= d >email to [email protected] and include SUBSCRIBE >your-email-address in the subject of your message. > > Copyright 1999 Carnegie Mellon University. > Conditions for use, disclaimers, and sponsorship information can = be >found in > http://www.cert.org/legal_stuff.html. > > * "CERT" and "CERT Coordination Center" are registered in the U.S. >Patent and Trademark Office > >NO WARRANTY >Any material furnished by Carnegie Mellon University and the Software >Engineering Institute is furnished on an "as is" basis. Carnegie Mellon >University makes no warranties of any kind, either expressed or implied = as >to any matter including, but not limited to, warranty of fitness for a >particular purpose or merchantability, exclusivity or results obtained f= rom >use of the material. Carnegie Mellon University does not make any warran= ty >of any kind with respect to freedom from patent, trademark, or copyright >infringement. >__________________________ > >As in the past, send ALL "virus warnings" to me. Don't post them to the >List. If, as in this case, a genuine virus exists, I'll post it. Most >warnings are hoaxes. > >For information on virus hoaxes and urban legends see > > http://ciac.llnl.gov/ciac/CIACHoaxes.html > > http://www.kumite.com/myths/ > >The next time you read a "warning", go to one or both of these web sites= to >get the facts. > >The above approved warning was sent to the SUTTON List by > >Milo Sutton, SUTTON List Owner >415 2nd Street >Hermosa Beach, CA 90254-4602 >Primary Email address: [email protected] >URL - http://www.geocities.com/Heartland/5248/ > >. > > > > > > >=3D=3D=3D=3D SUTTON Mailing List =3D=3D=3D=3D > >Also, post your query to the SUTTON BULLETIN board -- >http://www.geocities.com/Heartland/5248/genconnect.html > > > --------------2A2D51736D--

    04/24/1999 10:27:33