OT: Attachments help..

James Ellis Nov 29, 2001

As somebody who works in the web development profession I'd thought I would
share with all of you some ways of avoiding attachment viruses. I have a
large number of email aliases pointing at my inbox so I'm hit pretty
regularly..

1: Get a good virus protection system and keep the definition files up to
date.

2: Get a good non-Microsoft email client such as Eudora. Eudora drops all
attachments in one folder of your choice making it very easy to scan. Eudora
will not try and automatically open attachments either. It's free as well.

3: Avoid opening attachments that have a double extension such as
file.txt.exe, file.doc.pif. This is a cheap trick designed to fool
unsuspecting users into thinking they have a txt or doc file when in fact
its an exe or pif.
This may be difficult to pickup as some email clients only display the first
extension.

4: Never open any attachment unless you are absolutely sure you are supposed
to receive it.
Email subject headers generated by a virus are usually very simple and have
bad English eg "Take a look to this file.."

If unsure - delete it, then send the sender an email asking if they sent the
file to you. They can always send it again.

5: If you have access to a websites logfiles, never visit a requesting site
that is generating failure notices with a Windows file path on a Linux
server. I did this once and received an unwelcome visit from Nimda.

6: Invest in a Firewall that will allow you to decide which programs access
the net and when.

7. The great majority of viruses will propagate only if the user opens the
infected file. I believe some older versions of Outlook were set by default
to auto open files when they were received, though.
(I have deleted Oultook from my system - it's not the best :> )

Following these points has kept my PCs clean for the last 5 years. Hope this
helps all other guiders to keep those viruses at bay..

Regards

James



Jost,

This is good, thanks.

I opened the attachments on "Digest number 327" on tuesdayevening (WET). It
took me two days to get rid of te ^&*$.
(my last virusscanner update was from before de launch off the 'Badtrans"
virus, it infects kernel32.dll and couldn't be cleaned. After deleting it
there is no way to startup windows)

I replied a mail to this group just after I got infected. ( nov 27, 20.54
WET) Hopefully it was clean and I believe so, but still a warning. After
sending this message a received a series of messages from different "system
anti-virus administrators" that I was spreading a virus. They had timestamps
starting at 20.48. But they were all warnings about (very) old messages that
were resended from the "sent-items" box.
The attachments keep changing names all the time, as i could tell from the
different warnings, so do not open them. Delete the message ! (and go to the
map deleted items and delete it ones again from here if this isn't done
automatically) If you are running older versions of Windows (even ME without
last updates) an attached mail-virus may become active even without opening
it
And .. it's never to early to update your virusprotection software.

clear skies
Jan



_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp