Note: The Rootsweb Mailing Lists will be shut down on April 6, 2023. (More info)
RootsWeb.com Mailing Lists
Total: 1/1
    1. [MOSTODDA-L] Virus
    2. Phyllis Campbell
    3. This came from one of the people who manage a genealogy list AND I have had several other Emails today concerning this virus AND my daughter called me from Georgia to warn me about it and she heard about it on the news. It sounds like serious stuff. Phyllis ----- Original Message ----- From: Mary Hudson <[email protected]> > > > > >---------------------------------------------------------------- > >--------- RollaNet Announcement ([email protected]) -------- > >- - > >- This message is being sent to all RollaNet members from a - > >- RollaNet staffmember to notify you of important information - > >- regarding RollaNet activities, service outages, and/or other - > >- notices of interest to the RollaNet community. - > >- - > >---------------------------------------------------------------- > > > >MOREnet Security Advisory: "VBS/LoveLetter" Virus > > > >A new e-mail based Visual Basic script virus, VBS/LoveLetter, has been > found > >among MOREnet customers today. It spreads through e-mail as a chain letter. > >This virus targets Microsoft Outlook mail clients and mIRC chat clients, > and > >has already resulted in denial of service attacks against MOREnet customer > >mail servers. > > > >When it is run, the virus copies itself to the Windows System directory as > >MSKernel32.vbs and LOVE-LETTER-FOR-YOU.TXT.vbs; and to the Windows > directory > >as Win32DLL.vbs. The virus also adds itself to registry, so it will be > >executed when the system is restarted. Next the worm replaces the Internet > >Explorer home page with a link that points to an executable program, > >"WIN-BUGSFIX.exe". If the file is downloaded, the virus adds this to > >registry as well, causing that program to be executed when the system is > >restarted. > > > >The virus also creates "LOVE-LETTER-FOR-YOU.HTM" in the Windows System > >directory. This file contains the virus, and it will be sent using mIRC > >whenever the user joins an IRC channel. The virus also uses Microsoft > >Outlook to mass mail itself to every address in each and every Outlook > >address book. The headers from the message will read: > > > >Subject: ILOVEYOU > >Body: kindly check the attached LOVELETTER coming from me. > >Attachment: LOVE-LETTER-FOR-YOU.TXT.vbs > > > >The virus does additional damage to local files, but the above description > >should be sufficient to identify the virus locally. For additional > >information, see: > > > >http://www.datafellows.com/v-descs/love.htm > > > >Affected Software Versions > >======================== > > > >Directly Affected: > > > > Microsoft Outlook e-mail clients > > mIRC chat clients > > > >Indirectly Affected: > > > > Any user of a mail server clogged with mass mailed copies of the virus. > > > >What Customers Should Do > >======================== > > > >1. Do NOT open any e-mail with the headers: > > > >Subject: ILOVEYOU > >Body: kindly check the attached LOVELETTER coming from me. > >Attachment: LOVE-LETTER-FOR-YOU.TXT.vbs > > > >Simply deleting the message will prevent the virus from running, so long as > >you have not configured your e-mail client to automatically execute > >attachments. > > > >2. Update your current antivirus solution as soon as a patch becomes > >available though your vendor. > > > >3. If you discover a computer is infected, remove it from the network until > >it is disinfected with your current antivirus solution. This will minimize > >the impact on others. > > > >Check [email protected] (http://www.more.net/infoserv/newsbits/) for the > >latest news from MOREnet, and MOREnet Security > >(http://www.more.net/security/) for network security information and best > >practices. > > >

    05/04/2000 12:07:58