Re: Nimda?

2001-09-20 Thread Dierk Haasis

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Hello Douglas!

On Wednesday, September 19, 2001 at 10:49:33 PM you wrote:

 I found 3 readme.exe files on my system, from 1994  1996, 2 are 8
 kb  seem to mouse related, the other (the oldest) is 169 kb  is in
 the operating system's main directory.

 I assume that none of these are virus related. Is that assumption
 valid?

IME one can't rely on dates, there are a lot of ways to manipulate
them, some of them bugs in Win9x itself.

The question is, why should there be an executable Readme?

I use two things before discarding or deleting files I don't know of.
First I run a virus check with the newest definitions (F-Secure). If
that doesn't come up with anything I look at the file in a hex editor,
searching for telltale readable code in the ASCII portion.

This way I found the last big threat - this malware bringing with it
its own SMTP server - because I saw a call for the DUN.

When this doesn't bring up anything, I move the file to another hard
drive into a directory designated for superfluous/deletable files.
After a few days or weeks without trouble I delete these files.

Hope that helps.




- --
Dierk Haasis
http://www.Write4U.de

PGP keys available: mailto:[EMAIL PROTECTED]?Subject=SendMyPGPkeys

The Bat 1.54 Beta/9 on Windows 95 4.0 1212 C

Sonar no cuesta nada (Träumen kostet nichts.).

-BEGIN PGP SIGNATURE-
Version: PGP 6.5.8ckt
Comment: Privacy is the core element to Freedom!

iQA/AwUBO6mTifTo1oA8g8dLEQKCMwCgw5RY3fkSgpQgikWdC5eeTd6TAbYAoLTR
a9qVYK3003POk+LkVciwV8rp
=RgLW
-END PGP SIGNATURE-


--
__
Archives   : http://tbtech.thebat.dutaint.com
Moderators : mailto:[EMAIL PROTECTED]
Unsubscribe: mailto:[EMAIL PROTECTED]




Re: Nimda?

2001-09-20 Thread Peter Palmreuther

Hello Dwight,

On Wednesday, September 19, 2001 at 8:59:41 PM you wrote (at least in part):

DAC both that signature and yours show up as invalid here

OK ... one nice aspect on S/MIME is: you sometimes get a reason why the
cert/sig is invalid, is _anybody_ able to copy/paste this reason???

I got _all_ S/MIME-sigs shown valid ...

To see the reason why it's shown invalid double click the icon Invalid
Signature and press the View button lower left in the opening window.

The Invalidity reason is shown than in the second line after this text:
S/MIME Certificate Information

Thx Pit

-- 
Regards
Peter Palmreuthermailto:[EMAIL PROTECTED]
(The Bat! v1.54 Beta/9 on Windows NT 5.0 Build 2195 Service Pack 2)

Beyond good and evil lies North Dakota.


-- 
__
Archives   : http://tbtech.thebat.dutaint.com
Moderators : mailto:[EMAIL PROTECTED]
Unsubscribe: mailto:[EMAIL PROTECTED]