HP3000-L Archives

August 2000, Week 1

HP3000-L@RAVEN.UTC.EDU

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Neil Armstrong <[log in to unmask]>
Reply To:
Neil Armstrong <[log in to unmask]>
Date:
Fri, 4 Aug 2000 09:52:17 -0600
Content-Type:
text/plain
Parts/Attachments:
text/plain (165 lines)
It would seem that someone is monitoring this list and saw that a Windows
Scripting
Host file, which ended in an extension of .js was posted. It is these
scripts that are typically
used to write viruses in. People send them as attached files and open them
and they
run and do things to your system. Usually bad things.

This is just a guess.

Neil Armstrong

----- Original Message -----
From: <[log in to unmask]>
To: <[log in to unmask]>
Sent: Friday, August 04, 2000 9:22 AM
Subject: WARNING. You sent a potential virus or unauthorised code






Does anyone know what the following c - - p is ?
I have just received the message *3* times.
Tad.
---------------------- Envoyé par Tad BOCHAN/Securities_Services/FR/PARIBAS
le
04/08/2000 17:18 ---------------------------

Internet

From:     [log in to unmask] on 04/08/2000 15:24 GMT



Pour :    HP3000-L

cc :

ccc:  Tad BOCHAN

Objet :   [HP3000-L] WARNING. You sent a potential virus or unauthorised
      code




___________________________________________________________

This message and any attachments (the "message") are intended solely for
the addressees and are confidential.  If you receive this message in error,
please delete it and immediately notify the sender.

Any use not in accord with its purpose, any dissemination or disclosure,
either whole or patial, is prohibited except formal approval.

The internet can not guarantee the integrity of this message.  BNP PARIBAS
(and its subsidiaries) shall (will) not therefore be liable for the message
if modified.
                      ---------------------------------------------

Ce message et toutes les pieces jointes (ci-apres le "message") sont
etablis a l'intention exclusive de ses destinataires et sont confidentiels.
Si vous recevez ce message par erreur, merci de le detruire et d'en avertir
immediatement l'expediteur.

Toute utilisation de ce message non conforme a sa destination, toute
diffusion ou toute publication, totale ou partielle, est interdite, sauf
autorisation expresse.

L'internet ne permettant pas d'assurer l'integrite de ce message, BNP
PARIBAS (et ses filiales) decline(nt) toute responsabilite au titre de ce
message, dans l'hypothese ou il aurait ete modifie.
___________________________________________________________



----------------------------------------------------------------------------
----


>
> The Star Scanning System discovered a potential virus
> or unauthorised code in a message sent by you.
>
> The message was diverted into the virus holding pen on
> mail server mail-server-14.star.net.uk (id 16453_965402670)
> and will be held for 10 days before being destroyed.
>
> ------------------------------------------------
> To help identify the message:
>
> The message was titled 'Re: Eugene Sighted on ABC Free Speech Special'
> The message date was Fri, 4 Aug 2000 09:04:44 -0600
> The message identifier was <[log in to unmask]>
> The message was detected on server mail-server-14.star.net.uk
> The message recipients were
>     [log in to unmask]
>
>
> ------------------------------------------------
> What was it:
>
> Scanner 1 (Skeptic) reported the following:
>
> mailid = 0
> mailid = 16453_*
> Skeptic searching for 18 viruses
> Checking /var/qmail/queue/split/0/ for 16453_*
> >>> Possible Virus 'JS.Worm' variant found in '16453_1U_sample.js'.
Heuristics
> score: 250
>
>
> ------------------------------------------------
> Did the mail reach any recipients?
>
> If you are a customer of Star Internet, then the
> mail has been intercepted, and will not reach any
> recipients. Depending on your configuration, the
> intended recipients may or may not have received a
> warning message similar to this.
>
> If you are not a customer of Star Internet, then
> only the mail sent to customers of Star Internet
> has been intercepted. Mail to other recipients
> will not have been stopped. All recipients will
> have received a warning message similar to this.
> ------------------------------------------------
> What now?
>
> To find information on the scanner that detected the virus
> use the following links:
>
> NAI uvscan:           http://www.nai.com
> Cybersoft vfind:      http://www.cyber.com
> F-Secure:             http://www.f-secure.com
>
> You may be able to find more information on the virus detected
> from the following information sites:
>
> http://www.f-secure.com/virus-info/
> http://vil.nai.com/
>
> If your virus scanner does not detect a virus, do not attempt
> to send the mail again - our virus scanners will still detect
> a virus. You should contact our support department to
> resolve the problem, quoting virus pen number 16453_965402670,
> mail server mail-server-14.star.net.uk.
>
> If you need more information, or if you believe this to be a
> false alarm, please contact your local helpdesk / administrator,
> or contact Star Support on:
>    +44 (0)1285 884433
> or [log in to unmask]
>
>
> ________________________________________________________________________
> This message has been checked for all known viruses, by Star Internet,
> delivered through the MessageLabs Virus Control Centre.
> For further information visit:
> http://www.star.net.uk/stats.asp
>

ATOM RSS1 RSS2