>
>i received a suspicious e mail on both the silver and Rife lists.  i did
not
>try to open it ... the file monica.exe reminded me of melissa.  a few
>minutes later i received this virus warning.   a few hours later someone
>sent the suspicious letter to the silver list.  it starts out with a link
to
>stewart on a baby blue background.
>
>careful.
>
>jd
>
>
>-----Original Message-----
>From: Gary Hawkins <[email protected]>
>To: Bill Kingsbury <[email protected]>; [email protected]
><[email protected]>
>Date: Saturday, December 18, 1999 6:10 AM
>Subject: RE: [RF]: New Virus in Rife message - W32.NewApt.Worm noarc
>
>
>>Did anyone else receive a message with attachments like that?
>>
>>I did not.  Nor do I see any messages from [email protected].
>>Nor is such a person on the list at this moment, nor does
>>the name "Dwight Lorenz" appear in the archives anywhere over
>>the last year at least.
>>
>>Since he is not on the list, my best guess would be that the
>>rife list address was in his contacts list from the past, that
>>his system got infected, and perpetuated itself using the
>>rife list address as one of the next victims.  But the message
>>doesn't appear to have gone through to the list, so it's hard to
>>figure how it got through to anyone.
>>
>>Gary H.
>>
>>> -----Original Message-----
>>> From: Bill Kingsbury [mailto:[email protected]]
>>> Sent: Friday, December 17, 1999 7:02 PM
>>> To: [email protected]
>>> Subject: [RF]: New Virus in Rife message - W32.NewApt.Worm noarc
>>>
>>>
>>> Warning --
>>>  A "Dwight Lorenz" is passing this W32.NewApt.Worm virus -
>>> this time while responding to a Rife List message....
>>> Note:  "Dwight Lorenz" has NOT posted to this list since
>>> last August - if ever.
>>> Has any one else received this message, too?  Be careful !
>>> ..Bill
>>> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>>> ----- Infected Message Follows -----
>>>
>>> From: Dwight Lorenz <[email protected]>
>>> To:   [email protected]
>>> Subj: [RF]: OT: THE CELL TOWER EMF PROBLEM  noarc
>>> Date: Fri, 17 Dec 1999 20:34:40 -0600
>>>
>>>
>>> >he, your lame client cant read HTML, haha.
>>> > click attachment to see some stunningly HOT stuff
>>> >
>>> >Attachment Converted: "C:\!!!COM\'ATTACH\RFOTTHEC.htm"
>>> >Attachment Converted: "C:\!!!COM\'ATTACH\monica.exe"  <---Virus
>>>
>>>
>>> ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>>> From: "Fred Langa" <[email protected]>
>>> Subject: [langalist] 16-Dec-99
>>>
>>> This past Wednesday, yet another worm came to light: the W32.NewApt.Worm
>>> It's so new the antivirus people are only just now developing
>>> detection and repair tools for it.  The worm will email itself out
>>> to others via
>>> Microsoft Outlook or Netscape Navigator.
>>>
>>> Symantec says:
>>>
>>>      When activated, the worm will display an error dialog and modify
>>>      the registry so the worm is reloaded each time the computer is
>>>      restarted.  The error message box will appear as [a message about
>>>      a missing DLL].
>>>
>>>      When received by email (and if you do not have an HTML capable
>>>      email client), the message body will be:
>>>
>>>           he, your lame client cant read HTML, haha.
>>>           click attachment to see some stunningly HOT stuff
>>>
>>>      Otherwise, the text will include a reference to a website and the
>>>      following message:
>>>
>>>           Hypercool Happy Year 2000 funny programs and animations..
>>>           We attached our recent animation from this
>>>           site in our mail ! Check it out!
>>>
>>>      Attached to the message will be one of the following file names:
>>>      g-zilla.exe, cooler3.exe, cooler1.exe, copier.exe, video.exe,
>>>      pirate.exe, goal1.exe, hog.exe, party.exe, saddam.exe, monica.exe,
>>>      boss.exe, farter.exe, cheeseburst.exe, panther.exe, theobbq.exe,
>>>      goal.exe, baby.exe, bboy.exe, cupid2.exe, fborfw.exe, casper.exe,
>>>      irnglant.exe, or gadget.exe
>>>
>>>      The worm will add the following registry key:
>>>           HKLM/Software/Microsoft/Windows/Command/Run/tpanew
>>>
>>>      To remove the worm from memory, remove the above registry key and
>>>      then restart. Delete all infected files.
>>>
>>> And update your anti-virus definition files; most AV vendors will have
>>> a fix for this very soon.
>>>
>>>
>>>
>>>
>>>
>>>
>>
>>
>
>
>


__________________________________________
NetZero - Defenders of the Free World
Get your FREE Internet Access and Email at
http://www.netzero.net/download/index.html


--
The silver-list is a moderated forum for discussion of colloidal silver.

To join or quit silver-list or silver-digest send an e-mail message to: 
[email protected]  -or-  [email protected]
with the word subscribe or unsubscribe in the SUBJECT line.

To post, address your message to: [email protected]
Silver-list archive: http://escribe.com/health/thesilverlist/index.html
List maintainer: Mike Devour <[email protected]>