Subject: An Appology Offered - Escaped Virus
Date: Dec 9 06:18:31 2001
From: John & Loraine Allinger - jonymike at pacifier.com


Dear E-mailer,
This past week an E-mail virus escaped from our computer. It arrived in
the guise of a picture within a Word document. We did not intend for it to
escape, but were unaware of its existence until after we mistakenly opened
the attachment and activated the virus. We apologize for our lapse in
vigilance.
From an e-mail received from the Linfield College's computer network
folks we learned the following:
----- Original Message -----
From: <virus-wall at linfield.edu>
To: <jonymike at pacifier.com>
Sent: Monday, December 03, 2001 12:54 PM
Subject: Virus Alert
Warning! On 12/03/2001 12:54:21 in a message you sent to simo at linfield.edu,
the WORM_BADTRANS.B virus was detected in the attached file:
NEWS_DOC.DOC.scr and removed. DO NOT REPLY DIRECTLY TO THIS EMAIL. To
learn more, go to <http://www.linfield.edu/support/tips/virus.html>. If
you have further questions, send email to Support at linfield.edu.

AVERT ANTI-VIRUS RESEARCH SITE
To see the latest information about emerging virus threats, submit samples
of potentially infected files, and download updated scanning engine files,
EXTRA.DAT files, and similar anti-virus software for testing, visit the
AVERT research site at:
http://www.avertlabs.com.

I'd gone off-line and deleted the e-mail immediately upon clicking on it and
seeing the second extension to the attachment PICS.DOC.scr attached to a
seeming reply to a birding posting from this computer earlier this summer.
At that time my hard-drive and phone connection were working independent of
my input! To see if I was successful, I tried going on-line again, only to
learn that it had moved its nefarious self to another location within the
computer. Picked up a more recent copy of McAFEE VIRUS SCAN and it found
the infected file: C:\WINDOWS\SYSTEM\KERNEL32.EXE which it offered to clean
with a tag that it might delete it. So, in a manner I'd discovered earlier,
a user unfriendly McAFEE program fashion, it deleted the file - giving no
clue as to how to restore it so I could make windows work. There I was, no
way to go online and find out how to correct the problem. Turned out that
both McAFEE and the virus had apparently modified the AUTOEXEC.BAT -- that
because I had to rename the third file back autoexec.bat after giving bogus
file extensions (the three letter tags after the period) to the most recent
autoexec files. Now it may have been that the virus or worm thwarted
McAFEE's attempt to restore the computer to a functioning system.
With autoexec.bat restored to a working version I was able to run
windows and then renamed WIN.COM to WIN.OLD was able to reinstall Windows
from the CD-ROM installation disk (or is it disc?). WHOOPEE! Following
that it has been a matter of changing the settings -- The new McAFEE had an
internet filter that stopped all communications with the server as soon as
it responded. That took awhile to resolve. And MS Outlook Express wouldn't
download mail -- our son figured out what setting was reconfigured with the
WINDOWS reinstallation and we are now back on-line. Like I said, WHOOPEE!
And a big BOO! to the anti-social jerk who would rather destroy the
tenuous works of others than build on them and reinforce them to make
society a better place. This person is much like a small child knocking
down the construction of an older sibling. And I'm certain the analogy to
the acts of September 11th haven't escaped you. -- I would admonish
perpetrators of these kinds of acts to join society by 'growing up' and
getting beyond the easy, attention getting phase of childhood
destructiveness.
We apologize for the harm that has been caused you. We want you to know
that we in no way intended for something like this to happen and a usually
very diligent about deleting suspect e-mails, especially those with
attachments from sources we don't know. Just got suckered on that one!
Perhaps I was really too tired to be at the computer.
John & Loraine