VIRUS-DISCUSSION-L Archives
Archiver > VIRUS-DISCUSSION > 2000-01 > 0948327540
From: Carol C-H <>
Subject: Re: [VIR] Hello!!
Date: Wed, 19 Jan 2000 18:19:00 -0600
References: <17.bb6269.25b79587@aol.com><17.bb6269.25b79587@aol.com><17.bb6269.25b79587@aol.com>
In-Reply-To: <5-F_sD.A.YdG.w_kh4@bl-10.rootsweb.com>
And the e-mail sent out of the infected person's mailbox sometimes looks to
be from another innocent person (or e-mail list!) whose e-address is on a
post in the infected person's mailbox! To find more about this
particular virus, go to http://vil.mcafee.com/vil/wm10475.asp
Carol
At ,Gus Carroll wrote:
>I am also new to this list, but have seen this problem discussed on a
>couple of other Rootsweb Lists.
>
>
> From a 20 December 99 ( McAfee.com Dispatch ), they are talking about a
> W32/NewApt.worm which arrives as an email attachment.
>
>****************************************************
>The worm is in the attachment, which has a name chosen
>randomly from the following list:
>
> baby.exe, bboy.exe, boss.exe, casper.exe, chestburst.exe,
> cooler1.exe, cooler3.exe, copier.exe, cupid2.exe,
> farter.exe, fborfw.exe, goal.exe, goal1.exe, g-zilla.exe,
> irngiant.exe, hog.exe, monica.exe, panther.exe,
> panthr.exe, party.exe, pirate.exe, s.exe, saddam.exe,
> theobbq.exe, video.exe.
>
>If the worm is run, the following dummy error message
>appears:
>
> The dinamic link library giface.dll could not be found in
> the specified path [list of directory names]
>
>Note the misspelling of the word "dynamic".
>
>If the worm detects that Outlook Express is installed, it
>will search for messages received and build a list of
>addresses. The next time Windows is booted, the worm waits
>an unspecified amount of time and then attempts to send
>itself to one of the addresses in its list, using the
>format described above.
>****************************************************
>
>There are virus signature files available for most of the antivirus
>programs for this Worm.
>
>L8r,
>
>Sarge aka Gus
>
>
>^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>Sarge's Stuff Joke List: <G - R rated>, daily jokes,
>Send blank email to
>^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
>
>
>----------
> > Hi Listers,
> >
> > I am new to this list, so if I am not doing this right please let me know.
> >
> > There has been a problem on one of my Rootsweb lists. I know that
> attachments
> > cannot get through to Rootsweb lists because they are bounced back. But
> what
> > is happening to several people on the list is, they are receiving what
> looks
> > like a reply from something posted to the list at an earlier time, as
> though
> > someone is going through the archives and picking out old mail, then
> > attaching their worm/virus to it and sending it back to the original sender
> > of the e-mail. The name on this particular virus is Saddam.exe. Another
> > person on the list said that what is happening is that a member of the list
> > has the virus and it have invaded their address book, and is sending the
> > e-mail out from there.
> >
> > Does anyone know anything about this, and are other lists that ya'll are on
> > having this same problem? I would hate to think that we have a disgruntled
> > exlister getting even for something, but I guess the possibility is
> there. I
> > don't know squat about worms/viruses except not to open an attachment if I
> > don't know the sender.
> >
> > Thanks for any input.
> >
> > Judy
>
>
>==============================
>The RootsWeb WorldConnect Project:
>12.8 million individuals and counting.
>http://worldconnect.genealogy.rootsweb.com/
Carol C-H <> http://www2.netdoor.com/~cch/
Put off thy cares with thy clothes; so shall thee strengthen thy labor, and
so thy labor sweeten thy rest. ~Plutarch~
This thread:
| Re: [VIR] Hello!! by Carol C-H <> |