Important you read this!
 
Archibald Bard
 
----- Original Message -----
Sent: Saturday, January 12, 2002 6:16 PM
Subject: [rootsofterror] Some Virus Info

Don't open attachments. One of the best ways to prevent virus infections is not to open attachments (click on paperclip icons (the lower larger one) or double-click the subject lines and choose 'Open'), especially when dangerous viruses are being actively circulated. Even if the e-mail is from a known source, be careful. A few viruses take the mailing lists from an infected computer and send out new messages with its destructive payload attached. Always scan the attached files first for viruses. Unless it's a file or an image you are expecting, delete it, twice.

The Right-Click Scan Method

Always click the lower paperclip icon of any e-mail with a small or large paperclip icon indicating an attachment is present; choose 'save to disk'; Navigate to where the attachment was saved; Right-click the attachment and choose 'Scan with (your anti-virus)'. If the attachment is infected right-click it and choose Delete. Delete the associated e-mail from the Inbox and then the Deleted Items folder.

Why you shouldn't hide your file extensions (Windows hides them by default)
    
http://www.irchelp.org/irchelp/security/trojanext.html
Microsoft hides some extensions even if you say 'show all' (pif, lnk, shs, shb are probably the important ones)
    
http://www.pc-help.org/security/scrap.htm
Which extensions are dangerous?
    
http://support.microsoft.com/support/kb/articles/q262/6/31.asp?LN=EN-US&SD=gn&FR=0
       or
    
http://www.gladius.f9.co.uk/virus.html
       or
    
http://diamond-back.com/fileextensions.html
Need a list of all file extensions?
    
http://filext.com/
       or
    
http://www.windrivers.com/tech/filext.htm
       or
    
http://extsearch.com/
       or
    
http://www.acronymfinder.com <- excellent resource IMHO - search for acronyms and file extensions

Prevent future VBS and ActiveX viruses:
Disable Embedded Scripting:
    
http://www.sarc.com/avcenter/security/Content/2000_05_26_a_i_dES.html
     http://www.cert.org/tech_tips/malicious_code_FAQ.html#steps
Disable Windows Scripting Host:
    
http://service1.symantec.com/sarc/sarc.nsf/html/win.script.hosting.html
Note: Windows Scripting Host may be used by some programs including Windows Update. That's why I like to temporarily disable WSH using Symantec's utility rather than permanently remove it. See the article at http://www.zdnet.com/zdhelp/stories/main/0,5594,2568111,00.html to help you make an informed decision.

Keep your virus definitions up to date. McAfee should have caught it if you had scanned it before running the attachment. Do not rely on the email-scanning feature of your anti-virus program.

Reply via email to