[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [RT] VIRUS WARNINGrepley to Don



PureBytes Links

Trading Reference Links

Please repost House call site deleted it and emptied file, due to anothe Tom
Alexander post with a virus that loaded without opening a file , just by
highlighting the e-mail to delete and the worm tried to load through a temp
internet file called Card.pif . Nortan caught it but , this is really out of
hand here.
----- Original Message -----
From: "Don Ewers" <dbewers@xxxxxxxxxxxxx>
To: <realtraders@xxxxxxxxxxxxxxx>
Sent: Monday, November 26, 2001 5:19 PM
Subject: Re: [RT] VIRUS WARNING


> Peter, et all
> Thanks for the "House Call" site.  Interestingly when I went there and
> scanned my computer nothing was found too?
>
> I then read the file under the "Virus Info tab" for the "WORM_BADTRANS.B
> (click on it) and did the search they recommended under the solution (I
> could not get %System%\CP_25389.NLS to run but just CP_25389>NLS did find
a
> file).  I deleted it as instructed, as well as the file under regedit they
> recommend then restarted the computer.
>
> I then went back in and ran the free scan and "this time" five
WORM_BADTRAN
> files were found which I deleted (not sure why they did not show the first
> time, perhaps the NLS file covers them up)?
>
> It now says I am Virus free.  I like Earl do not run anti-virus software
due
> to the problems I have had with it slowing down the PC's substantially.  I
> too am extremely carefull about what I open.  As mentioned on the yahoo
post
> on this worm it opens itself.  I did however discover my OE5 was "not" set
> to the highest setting under Tool >Option>Security as I thought it was and
> that has been corrected (Earl's advice several times to this list) which
he
> feels would have stopped it I believe (correct me if I am wrong Earl, it
did
> stop it on yours)?
>
> It might be helpful if all on the list search for the above file and if
> found go through the process or update their virus software.
>
> One other note, Lee the  !0000 did not stop the spread, I understand, so
not
> a cure-all?
>
> My guess it came from that early email BL and Clyde saw a virus on?
Problem
> being there is no way to delete it since it opens as soon as the message
is
> tabbed down to.
> don ewers
>
> ----- Original Message -----
> From: "Peter Gialames" <investor@xxxxxxxxxxxxx>
> To: <realtraders@xxxxxxxxxxxxxxx>
> Sent: Monday, November 26, 2001 1:49 PM
> Subject: RE: [RT] VIRUS WARNING
>
>
> > Trend Micro PC-cillin antivirus scanner (web based).  I have used it,
but
> > have never found any viruses (good for me - bad for the program if I
> > actually do have a virus).
> >
> > Also, Script Sentry does a good job of intercepting rogue
> > scripts/applications/macros.  It actually just intercepted an email from
> > this list sent to me privately.
> >
> > Peter Gialames
> >
> > -----Original Message-----
> > From: Michael Ferguson [mailto:wl7bdn@xxxxxxxxxxxxx]
> > Sent: Monday, November 26, 2001 2:43 PM
> > To: realtraders@xxxxxxxxxxxxxxx
> > Subject: Re: [RT] VIRUS WARNING
> >
> >
> > Peter,
> >
> > What exactly is that site? I am a little nervous about clicking
something
> > that looks so unusual.
> >
> > Michael
> >
> >
> > ----- Original Message -----
> > From: "Peter Gialames" <investor@xxxxxxxxxxxxx>
> > To: <realtraders@xxxxxxxxxxxxxxx>
> > Sent: Monday, November 26, 2001 13:32
> > Subject: RE: [RT] VIRUS WARNING
> >
> >
> > > http://housecall.antivirus.com/housecall/start_pcc.asp will help.
> > >
> > > Peter Gialames
> > >
> > > -----Original Message-----
> > > From: Don Ewers [mailto:dbewers@xxxxxxxxxxxxx]
> > > Sent: Monday, November 26, 2001 2:15 PM
> > > To: realtraders@xxxxxxxxxxxxxxx
> > > Subject: Re: [RT] VIRUS WARNING
> > >
> > >
> > > I think those that have used that trick in your address book !0000 as
> the
> > > first email address keeps it from spreading , but it still resides on
> our
> > > computers?
> > >
> > > Now what do we do??
> > > don ewers
> > >
> > > ----- Original Message -----
> > > From: "John Nelson" <trader@xxxxxxxxxxxxxxx>
> > > To: <realtraders@xxxxxxxxxxxxxxx>
> > > Sent: Monday, November 26, 2001 1:10 PM
> > > Subject: RE: [RT] VIRUS WARNING
> > >
> > >
> > > > You don't even have to open the attachment on this one!!!!
> > > >
> > > > http://biz.yahoo.com/rf/011126/n26355186_2.html
> > > >
> > > >   -----Original Message-----
> > > >   From: I4Lothian@xxxxxxx [mailto:I4Lothian@xxxxxxx]
> > > >   Sent: Monday, November 26, 2001 2:05 PM
> > > >   To: realtraders@xxxxxxxxxxxxxxx
> > > >   Subject: Re: [RT] VIRUS WARNING
> > > >
> > > >
> > > >   The virus I received from Tom had a MP3.pif name on it with some
> other
> > > > name before the MP3 part.  I also received another .pif file 5
minutes
> > > > before from someone else with an MP3.pif component on it.
> > > >
> > > >   Looks like the title of the file may morph.
> > > >
> > > >   Regards,
> > > >
> > > >   John J. Lothian
> > > >
> > > >   Futures trading involves financial risk, lots of it!
> > > >
> > > >   In a message dated 11/26/2001 12:27:23 PM Central Standard Time,
> > > > eadamy@xxxxxxxxxx writes:
> > > >
> > > >
> > > >
> > > >     Filename was HAMSTER.DOC.pif. I've noticed that a number of
virus'
> > are
> > > > now
> > > >     using double dot file names, quite likely to fool the unwary
into
> > > > opening
> > > >     the file based on the "first extension".
> > > >
> > > >     Earl
> > > >
> > > >
> > > >
> > > >         Yahoo! Groups Sponsor
> > > >               ADVERTISEMENT
> > > >
> > > >
> > > >
> > > >
> > > >   To unsubscribe from this group, send an email to:
> > > >   realtraders-unsubscribe@xxxxxxxxxxxxxxx
> > > >
> > > >
> > > >
> > > >   Your use of Yahoo! Groups is subject to the Yahoo! Terms of
Service.
> > > >
> > > >
> > >
> > >
> > >
> > > To unsubscribe from this group, send an email to:
> > > realtraders-unsubscribe@xxxxxxxxxxxxxxx
> > >
> > >
> > >
> > > Your use of Yahoo! Groups is subject to
> http://docs.yahoo.com/info/terms/
> > >
> > >
> > >
> > >
> > >
> > > To unsubscribe from this group, send an email to:
> > > realtraders-unsubscribe@xxxxxxxxxxxxxxx
> > >
> > >
> > >
> > > Your use of Yahoo! Groups is subject to
> http://docs.yahoo.com/info/terms/
> > >
> > >
> >
> >
> >
> > To unsubscribe from this group, send an email to:
> > realtraders-unsubscribe@xxxxxxxxxxxxxxx
> >
> >
> >
> > Your use of Yahoo! Groups is subject to
http://docs.yahoo.com/info/terms/
> >
> >
> >
> >
> >
> > To unsubscribe from this group, send an email to:
> > realtraders-unsubscribe@xxxxxxxxxxxxxxx
> >
> >
> >
> > Your use of Yahoo! Groups is subject to
http://docs.yahoo.com/info/terms/
> >
> >
>
>
>
> To unsubscribe from this group, send an email to:
> realtraders-unsubscribe@xxxxxxxxxxxxxxx
>
>
>
> Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/
>
>
>


------------------------ Yahoo! Groups Sponsor ---------------------~-->
Universal Inkjet Refill Kit $29.95
Refill any ink cartridge for less!
Includes black and color ink.
http://us.click.yahoo.com/Vv.L9D/MkNDAA/ySSFAA/zMEolB/TM
---------------------------------------------------------------------~->

To unsubscribe from this group, send an email to:
realtraders-unsubscribe@xxxxxxxxxxxxxxx

 

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/