BBFACSTAFF-L Archives

August 2003

BBFACSTAFF-L@BARUCH.LISTSERV.CUNY.EDU

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Public Announcements <[log in to unmask]>
Reply To:
Public Announcements <[log in to unmask]>
Date:
Tue, 19 Aug 2003 17:52:42 -0400
Content-Type:
text/plain
Parts/Attachments:
text/plain (47 lines)
Earlier this morning we detected a worm virus (Sobig) that was being sent
through the Baruch email systems. This is a new worm that was only
introduced this morning, so the college's commercial antivirus software did
not yet have the definition files necessary to delete it. As a result, we
had to temporarily shut down the mail servers until a remedy was available.
Within two hours the program to disarm the worm virus was made available to
us and installed on the Antivirus Server and automatically sent to all users.

We are aware that many worm e-mails are still being sent to your mailbox.
Our antivirus software is removing the infected attachments, so the e-mails
are primarily a nuisance. We are identifying the PCs on campus that are
sending out the e-mails and shutting them down as quickly as we can. In the
interim, please delete all of these messages as they come in.  Please do not
reply to any of them, including anything from "System Anti-Virus
Administrator" or "Mailer-Daemon" - just delete them.  However, you should
contact the Help Desk if you get any new message which contains any of the
following files as an attachment:

your_document.pif
document_all.pif
thank_you.pif
your_details.pif
details.pif
document_9446.pif
application.pif
wicked_scr.scr
movie0045.pif


If you do receive a message with one of these attachment files, please DO
NOT open the attachment.   Delete the message and run Norton Antivirus on
your machine.
Check the version of Norton Antivirus by double clicking on the Norton icon
(yellow shield) on the lower right hand corner of your screen.
Confirm that the version of the Virus Definition File is 8/19/2003 rev 3. If
it is not that version contact the BCTC Help Desk at (646) 312-1010.

To remove any worm on your machine, start Norton Antivirus.
After the program begins, double click on SCAN on the left side of your screen.
Click on SCAN COMPUTER
On right side of screen
Click on empty white box next to LOCAL DISK C: - a check mark will appear in
the white box.
Click SCAN button.
When the scan completes contact the BCTC Help Desk at (646) 312-1010 if the
scan detected the worm and the status is "infected".

ATOM RSS1 RSS2