ENG-WARKS-BIRMINGHAM-L Archives

Archiver > ENG-WARKS-BIRMINGHAM > 2001-11 > 1004927562


From: "Kathleen's Korner" <>
Subject: [B'ham] Virus Heads Up! (from Admin -- Please Read!)
Date: Sun, 4 Nov 2001 19:32:42 -0700


Hello, Brummies . . .
As most of you are already probably aware, thanks to Andrea's quick
alert to Zena and her list warning to you, those ugly, nasty virus
critters are out and about again. For those experienced surfers out
there, this is just a heads-up. For those still learning, read the
information that follows. I may help ease your mind and make you less
fearful of viruses.

A caution! This you've heard repeatedly, but merits saying once
again. *DO NOT* open any attachment you either were not expecting or
were not alerted had been sent to you.

An added protection trick! If you're using Outlook Express (can't
speak for other mail clients, sorry) and you get an email with an
attachment, try this . . . It's perfectly safe. I've been doing it
forever and <knocking on wood> have yet to be infected despite the
thousands of viruses I've received.

Oh, BTW! Some AV programs *only* scan an attachment when you either
try to open it (and I'm not that brave . . . nor that stupid) or when
you save it as a file and perform a single file scan. McAfee is one .
. . I know, I use it! Doesn't mean it's a bad AV program, folks; just
means you have not know how to use it.

LOOK (at the CONTENTS of that ATTACHMENT) before you LEAP!
YES!! You can do that!
1. Shut off your Preview Window. That little guy auto-opens some
infected email and its users are asking for trouble.
2. Highlight the email in your Inbox Window with the attachment.
3. Right click, select Properties, Details tab and Message Source
button.
4. Now . . . Explore!
a. Review the email's message content, if there is one.
b. Look for the attachment's file name. An .exe .pif and
others are execute commands. Ahah! A clue!
c. Keep scrolling down until you come upon the contents of the
attachment. OE usually includes it inline in the code.
1. Don't be alarmed. You have *NOT* opened the attachment
doing this. You're only peeking at the coding.
2. Opening the actual attachment itself is what executes
the virus program.
3. If what you see looks like a packed conglomeration of
letters, numbers and characters . . . *no*
spacing . . . bets are IT'S A VIRUS!
4. Delete the entire email with attachment and empty
your Delete Folder also.
5. Run a full scan of you system, just as a precaution.
5. If you did the above and the contents of the attachment appear
normal, do this. (Write me if need help here.)
a. Open the email and save the attachment to My Docs.
b. Isolate and run a scan on just that file. (Typically if the
file is infected, you won't have to. Your AV program
will pick it up immediately and alert you.)
c. Still not sure? Inquire of the sender confirmation that he
sent the attachment and precisely what it contains.

When in doubt, DELETE is still your safest bet!

NOW a WARNING! There's a new kind of virus trap running around out
there. I've had half a dozen this weekend, alone. It comes in an
email, no attachment, and appears to resemble SPAM. However, it's not
the typical SPAM you can easily pick out. It's much more subtle and
more apt to raise your curiosity enough to take a peek. The peek
won't hurt!

What you must keep alert to is *any* email which offers you something
by clicking on a link to take go to the website. That alone is not
evil. What is are the one's that go on saying this "program
download" or whatever will *auto-execute" (or words to that effect)
the download upon entering the site and you needn't do anything
further. RIGHT! The site is infected. The auto-download is a virus
. . . and now you're fighting for your Cyber life.

Now I'm not saying *all* of these sites are evil or that they download
viruses, but are you willing to gamble? I'm not!

Reminder! If anyone thinks they received a virus from another member
of this List, please alert me at once. I'll temporarily unsub them
until we can make contact and help them get clean again so they can
rejoin us.

-- Kathleen
List Admin
[at Kathleen's Korner ]




This thread: