> >i received a suspicious e mail on both the silver and Rife lists. i did not >try to open it ... the file monica.exe reminded me of melissa. a few >minutes later i received this virus warning. a few hours later someone >sent the suspicious letter to the silver list. it starts out with a link to >stewart on a baby blue background. > >careful. > >jd > > >-----Original Message----- >From: Gary Hawkins <[email protected]> >To: Bill Kingsbury <[email protected]>; [email protected] ><[email protected]> >Date: Saturday, December 18, 1999 6:10 AM >Subject: RE: [RF]: New Virus in Rife message - W32.NewApt.Worm noarc > > >>Did anyone else receive a message with attachments like that? >> >>I did not. Nor do I see any messages from [email protected]. >>Nor is such a person on the list at this moment, nor does >>the name "Dwight Lorenz" appear in the archives anywhere over >>the last year at least. >> >>Since he is not on the list, my best guess would be that the >>rife list address was in his contacts list from the past, that >>his system got infected, and perpetuated itself using the >>rife list address as one of the next victims. But the message >>doesn't appear to have gone through to the list, so it's hard to >>figure how it got through to anyone. >> >>Gary H. >> >>> -----Original Message----- >>> From: Bill Kingsbury [mailto:[email protected]] >>> Sent: Friday, December 17, 1999 7:02 PM >>> To: [email protected] >>> Subject: [RF]: New Virus in Rife message - W32.NewApt.Worm noarc >>> >>> >>> Warning -- >>> A "Dwight Lorenz" is passing this W32.NewApt.Worm virus - >>> this time while responding to a Rife List message.... >>> Note: "Dwight Lorenz" has NOT posted to this list since >>> last August - if ever. >>> Has any one else received this message, too? Be careful ! >>> ..Bill >>> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >>> ----- Infected Message Follows ----- >>> >>> From: Dwight Lorenz <[email protected]> >>> To: [email protected] >>> Subj: [RF]: OT: THE CELL TOWER EMF PROBLEM noarc >>> Date: Fri, 17 Dec 1999 20:34:40 -0600 >>> >>> >>> >he, your lame client cant read HTML, haha. >>> > click attachment to see some stunningly HOT stuff >>> > >>> >Attachment Converted: "C:\!!!COM\'ATTACH\RFOTTHEC.htm" >>> >Attachment Converted: "C:\!!!COM\'ATTACH\monica.exe" <---Virus >>> >>> >>> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >>> From: "Fred Langa" <[email protected]> >>> Subject: [langalist] 16-Dec-99 >>> >>> This past Wednesday, yet another worm came to light: the W32.NewApt.Worm >>> It's so new the antivirus people are only just now developing >>> detection and repair tools for it. The worm will email itself out >>> to others via >>> Microsoft Outlook or Netscape Navigator. >>> >>> Symantec says: >>> >>> When activated, the worm will display an error dialog and modify >>> the registry so the worm is reloaded each time the computer is >>> restarted. The error message box will appear as [a message about >>> a missing DLL]. >>> >>> When received by email (and if you do not have an HTML capable >>> email client), the message body will be: >>> >>> he, your lame client cant read HTML, haha. >>> click attachment to see some stunningly HOT stuff >>> >>> Otherwise, the text will include a reference to a website and the >>> following message: >>> >>> Hypercool Happy Year 2000 funny programs and animations.. >>> We attached our recent animation from this >>> site in our mail ! Check it out! >>> >>> Attached to the message will be one of the following file names: >>> g-zilla.exe, cooler3.exe, cooler1.exe, copier.exe, video.exe, >>> pirate.exe, goal1.exe, hog.exe, party.exe, saddam.exe, monica.exe, >>> boss.exe, farter.exe, cheeseburst.exe, panther.exe, theobbq.exe, >>> goal.exe, baby.exe, bboy.exe, cupid2.exe, fborfw.exe, casper.exe, >>> irnglant.exe, or gadget.exe >>> >>> The worm will add the following registry key: >>> HKLM/Software/Microsoft/Windows/Command/Run/tpanew >>> >>> To remove the worm from memory, remove the above registry key and >>> then restart. Delete all infected files. >>> >>> And update your anti-virus definition files; most AV vendors will have >>> a fix for this very soon. >>> >>> >>> >>> >>> >>> >> >> > > >
__________________________________________ NetZero - Defenders of the Free World Get your FREE Internet Access and Email at http://www.netzero.net/download/index.html -- The silver-list is a moderated forum for discussion of colloidal silver. To join or quit silver-list or silver-digest send an e-mail message to: [email protected] -or- [email protected] with the word subscribe or unsubscribe in the SUBJECT line. To post, address your message to: [email protected] Silver-list archive: http://escribe.com/health/thesilverlist/index.html List maintainer: Mike Devour <[email protected]>

