LSTOWN-L Archives

LISTSERV List Owners' Forum

LSTOWN-L

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Topic: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Molly Beane <[log in to unmask]>
Mon, 23 Apr 2001 08:47:36 -0400
text/plain (28 lines)
Hello everyone,

Our list has two members whose computers have been infected by the new (as
of April 11) W32.Badtrans.13312@m worm.  Even though no attachments have
been sent to the list (all settings are active for screening these),
members are receiving bogus messages with worm attachments because it sends
itself off using a fake Reply message and a variety to anyone who has
posted recently.

Some other members have opened the attachments, thinking it was a
legitimate message from someone else on the list, and are in various stages
of cleaning up their computers.

I have put the identified infected senders on NOMAIL and asked them to let
me know when they have received my messages and cleaned their computers.

Is anyone else dealing with this and taking more drastic measures, such as
putting the list on hold to give people a chance to clean up their
computers and break the cycle before any more messages are posted?

Also, does anyone have any url pointers to changing an IP address for the
technically timid (this virus sends a computer's IP address to the worm
author, so in addition to cleaning up the virus files, and the registry,
this seems a prudent step)

thanks,
Molly

ATOM RSS1 RSS2