"Comet" virus - I got it, look out!!

Jon Page jonpage@mediaone.net
Sun, 04 Feb 2001 17:28:37 -0500


I received this from Zone Labs (which I use as a firewall) :

We need protection from websites too it seems.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Date: Mon, 29 Jan 2001 11:13:04 -0800
Content-Type: multipart/alternative; boundary="----Alt_Boundary_1"

The important combination of powerful firewall security and ad-blocking 
software is now available. With this special offer on ZoneAlarm™ Pro and 
AdSubtract Pro you can:
    * Save valuable time
    * Stop unwanted cookies
    * Block unwanted ads, pop-ups, animations, and music
    * Block IP addresses that run port scans
    * Prevent email attachment viruses from spreading
    * Protect your security settings
    * and much more!


This exclusive offer and special price is only
available for a limited time, so please act now!

Many programs used by hackers are designed to be servers. One of the ways 
ZoneAlarm protects you is by detecting server programs that are listening 
for connections and instructions from remote clients.

When ZoneAlarm detects a program acting as a server, the firewall blocks 
the incoming connection. This will protect you from identity/property theft 
through Trojan Horses. However, you may have programs (like ICQ or 
NetMeeting) that act as servers as part of their core functionality.

In the Programs Panel you can designate which programs you trust to be servers.

Simply follow the Allow Server column down and check the box next to 
appropriate progam(s). However, use discretion, never assign an application 
server rights unless you trust it and know it is required for it to operate 
properly.

Have a support question regarding ZoneAlarm? Send inquiries to 
support@zonelabs.com


© 1999-2001 Zone Labs, Inc., 7 Heron Street, San Francisco, CA 94103, USA.
All rights reserved. All other trademarks are the property of their 
respective owners.


At 01:42 PM 02/04/2001 -0600, you wrote:
>HEADS UP, there is a new virus put there that is VERY sneaky called
>"Comet" and it comes to you as a "pop-up" window.  I'm not certain what
>page I was looking at but it was something to do with searching for
>computer equipment info, (there is the catch).  A window popped up
>appearing as a system error message: "Notice a plug-in required needs
>updating, click ok to proceed"- or something like that.  Sounds
>legitimate.  So anyway after clicking okay "something" downloads and
>then a cute little application-looking window appears introducing itself
>as the "ultimate in computer web browsing" or some such thing.  It makes
>absolutely no since.  Realizing that this was something I didn't want
>and that I had been taken for what I thought was advertising, I deleted
>it... or did I???
>
>The next time I started the system up- it wouldn't.  The entire win.ini
>file was gone.  No way to fix it because Windows won't start.  A
>"start-up" disk doesn't help.  Then I discover that the BIOS has been
>screwed with.  This is one nasty bug!!
>
>Long of the short of it, the easiest cure was to go out and buy a new
>hard drive.  I could have reloaded Windows using a universal boot disk
>but that required reformatting of the hard drive which means I would
>have lost EVERYTHING.  I wanted more space anyway but not under these
>circumstances.  At this point with two hard drives connected I can
>transfer everything valuable to the new drive safely.  I already had two
>drives on my system so now I got three- now that is a lot of storage
>space!
>
>Moral of the story and a warning- if you see this pop-up, (or anything
>similar), RUN LIKE THE WIND!!!
>
>Rob Goodale, RPT
>Las Vegas, NV

Jon Page,   piano technician
Harwich Port, Cape Cod, Mass.
mailto:jonpage@mediaone.net
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



This PTG archive page provided courtesy of Moy Piano Service, LLC