Hi List members,
I usually do not post virus warnings on my lists until I know it is real
and not a hoax. This morning the WORM called "W32.NewApt.Worm" came
through to me. It looks like it came from the FRAME-L rootsweb mailing
list, but it "did not" go through the rootsweb list, it came from another
source. I received the post below from the FRAME-L list, so if anyone else
on the list received it also, the first thing to do is.....
"DELETE" the "VIDEO.EXE" FILE IMMEDIATELY.....DO NOT OPEN IT!!!!
#1: Rootsweb lists are incapable of sending or
receiving attachments and/or HTML mail, so you will not get this worm from a
Rootsweb list. #2: Please note that as far as we currently know this worm
only affects those using Outlook Express and Netscape Mail as their email
programs, but it is a clever worm that is constantly morphing so please be
aware. Now, several of you may have received mail that LOOKS like it is
from a Rootsweb list that is carrying the virus, but the important thing
here is that this worm is capable of "forging" it's to AND from lines so
that while it is not actually coming from a Rootsweb list, it looks like it
is. Rootsweb has posted information on this particular worm here:
http://helpdesk.rootsweb.com/virus1.html
that explains the "forging" and Symantec (the makers of Norton Antivirus)
has information about the worm and how to remove it as well at
http://www.symantec.com/avcenter/venc/data/worm.newapt.html
Basically the best rule of thumb is NEVER open an attachment you know
nothing about and if in doubt, email the "sender" to make sure that they
are actually trying to send you something. ALWAYS update your virus
software (i.e.. once a week is best) and ALWAYS scan any files before
opening. Below is the post that was sent on to us on the listowners list
by
MessageMates.com. Thanks Carole for the info!
Markie
Listowner
***********
Message that "looks like" it came from the FRAME LIST this morn.!
Date: Wed, 22 Dec 1999 00:25:46 -0800
X-From_: FRAME-D(a)rootsweb.com Wed Dec 22 00:25:39 1999
From: FRAME-D(a)rootsweb.com
Old-Date: Wed, 22 Dec 1999 00:24:35 -0800 (PST)
To: Frame-d-request(a)rootsweb.com
Subject: FRAME-D Digest V99 #12
X-Diagnostic: Submission size exceeds 20000 bytes
X-Envelope-To: FRAME-D-request
http://stuart.messagemates.com/index.html
Hypercool Happy New Year 2000 funny programs and animations...
We attached our recent animation from this site in our mail ! Check it out !
Attachment Converted: "c:\eudora\attach\video.exe"
***********************************
IMPORTANT NOTICE:
We have just learned that an email worm has been found circulating the
web referencing
MessageMates.com. This worm file is in no way connected
with
MessageMates.com. If you have received an email with a message that
reads:
he, your lame client cant read HTML, haha. click attachment to see some
stunningly HOT stuff
or
http://stuart.messagemates.com/index.html
Hypercool Happy Year 2000 funny programs and animationsÖ.
We attached our recent animation from this site in our mail! Check it
out!
Then you have been passed the Worm in question. It is a worm that
was created and set loose by someone who ís trying to spoil all of our
Holiday fun. Do not run the attachment included in the email and please
delete the email message immediately! What we know about this Worm so
far:
1. Symantec has named this worm: W32.NewApt.Worm.
2. Once opened/launched the worm will email itself out and reply to
messages in your mailbox.
3. The file being passed as an attachment is approximately 68K.
4. The subject line of this message will vary and may appear to be
a reply to something youíve previously sent.
5. The attachment is no way related to any
MessageMates.com
products.Ý
What you can do:
1. Read the details of this worm virus by checking with Symantec
at:
http://www.symantec.com/avcenter/index.html
2. If you receive a suspect email with an .exe attachment from
someone, first email them back and confirm that theyíve intended to send
you a MessageMate.
What we can tell you about
MessageMates.com:
1. Our millions of loyal users are our number one priority and we
are fully committed to providing software programs that are safe and
fun.
2. We never send out any unsolicited emails.
3. We never send out attachments.
4. Our files are 100% safe when downloaded directly from our web
site.
Please know that we at
MessageMates.com have worked tirelessly to earn
your trust and respect. We take great pride in our products and only
want our users to have a positive and entertaining experience with them.
Thank you for taking the time to read this very important notice. If you
have any questions or comments, please email me directly at
cheitmann(a)adtoolsinc.com
Chris Heitmann
Chief Operating Officer
Carole Rohrings
rohrbach(a)jnb.com