I corresponded with Paul on the 17th, is that how my name was gotten to be used, or are you saying I have the worm? Have sent no attachments anywhere in months. That was my subject heading sent to the list. I have latest Norton and also checked for the 3 files Paul mentioned and none were found on my computer. Thanks, Renea [email protected] TNGenWeb County Coordinator for Decatur Co, TN http://www.netease.net/decatur TNGenWeb County Coordinator for Perry Co, TN http://www.netease.net/perry Listowner Decatur, Henderson, Perry Cos, TN [email protected] -----Original Message----- From: Paul Beatty <[email protected]> To: [email protected] <[email protected]> Date: Wednesday, December 22, 1999 9:39 AM Subject: Re: [TNMARSHA] What's new!- The virus is still out there! >Karen, > >The message I got containing the NewApt worm was "from" >Renea; [email protected] >Subject: Re [TNMARSHA] TN Confederate Home > >FYI, > >This one is really insidious. I recognized the sender, subject, etc. The >message was in hypertext and gave a url to go to for "hypercool New Years >programs and animations." The attached file was named chestburst.exe (but it >could have been named any of 26 variations). I checked it with Norton >Anti-virus and it showed it clean. When I opened it, I got the worm. >F-Secure running in Windows detected but did not remove the virus. Norton, >with the latest upgrades never saw it until I tried to "send" the file to >A:. Then I got a warning. I finally restarted in DOS mode and deleted >chestburst.exe and dc4.exe (dc40xe). All subsequent scans show no further >infection. Thanks. > >Paul >----- Original Message ----- >From: Karen in Ky <[email protected]> >To: <[email protected]> >Sent: Tuesday, December 21, 1999 6:02 PM >Subject: Re: [TNMARSHA] What's new!- The virus is still out there! > > >> Hi Paul, >> It may look like the virus is coming from the list, but rootsweb doesn't >allow >> attachment, any email to the list with an attachment gets kicked back to >me. >> (Giving me lots of virus chances!) >> What happens is, the virus sends out messages to the addresses in your >address >> book, and it uses (forges) the subject lines of old emails. >> This website will tell you how to get rid of it. >> <"http://www.europe.f-secure.com/v-descs/newapt.htm">click</a> >> You may try calling your ISP, maybe someone there can walk you through >removing >> it. >> Good Luck, >> Karen >> >> Paul Beatty wrote: >> >> > Messages from this list are still being sent out containing this virus. >The >> > latest one I received was on 12/17/99. My system has been infected and >the >> > F-Secure program finds but will not eradicate it. The latest update for >> > Norton Ant-Virus does not detect this virus/worm! That's how I got it in >the >> > first place. Norton said the attachment was virus-free. >> > >> > Paul, Plagued in KY >> > ----- Original Message ----- >> > From: Karen in Ky <[email protected]> >> > To: <[email protected]> >> > Sent: Sunday, December 19, 1999 12:40 PM >> > Subject: [TNMARSHA] What's new! >> > >> > > Hi All, >> > > As we have flu season in the real world, it is also virus/worm >> > > season in the cyber world! Here is the latest one >> > > <"http://www.europe.f-secure.com/v-descs/newapt.htm">click</a> I >have >> > > already received it, but fortunately didn't open it! So be extra >> > > careful about opening any attachments! Better safe than in the repair >> > > shop!! <grin> And keep your Anti Virus programs updated regularly >> > > during the next few months, this isn't the only one out there! There >> > > are just as many hoaxes going around as there are real virus/worms: >> > > <"http://www.symantec.com/avcenter/hoax.html">click</a> >> > > >> > > I'm working on uploading some great new things for the Marshall Web >> > > site, should have them all completed by tonight or tomorrow!! I'll >> > > announce it the minute I get finished. >> > > Have a safe and happy holiday! >> > > Karen >> > > >> > > >> > > >> >> > >