If you are running any version of VirusScan other than Enterprise 7, you need to update now.
IMPORTANT NOTE: VirusScan Enterprise 7 will not run on Windows 98 machines. If you are still running Windows 98, you need to update to Windows 2000 or Windows XP.
Instructions for installing VirusScan Enterprise 7 are available online. Alternately, you can find them by going to For Staff-- Technology Items--Anti-Virus Information.
VirusScan Enterprise 7.0.0 was provided to field offices on the Scout CD that was sent in the July 13, 2003 transmittal package. You can also install VirusScan Enterprise 7 by using Scout over the network, but in most county offices this download will take a half hour to an hour to complete.
When you install VirusScan Enterprise 7, it will set up a schedule for automatically updating your virus definitions. VirusScan 7 will scan incoming messages and scan files when accessed. It will generally not do a regular scan of your entire hard drive (since it's scanning files as they arrive and as they're accessed). However, you can scan your hard drive at any time by right-clicking on the VShield icon in the lower right-hand corner of your computer screen and selecting 'On-Demand Scan.'
You can also update your virus definitions at any time (in between scheduled updates) by right-clicking on the VShield icon and selecting 'Update now' from the menu.
If you don't know what version of VirusScan you currently have, you can right-click on the VShield icon and select 'About VirusScan' or 'About VirusScan Enterprise'. You should have VirusScan Enterprise 7.0.0 or higher.
If you are not currently running any version of VirusScan, you need to install it immediately following the online instructions and, once you've installed VirusScan, you will likely want to download and run the latest version of Stinger.
Links in this post:
Instructions for installing VirusScan Enterprise 7: http://www.extension.iastate.edu/Comp/virus/installing_virusscan.htm
Download Stinger: http://vil.nai.com/vil/stinger
For Staff Pages: http://www.extension.iastate.edu/ForStaff/homepage.html
Technology Items: http://www.extension.iastate.edu/Comp/
Anti-Virus Information: http://www.extension.iastate.edu/Comp/virus/
W32/Bagle@MM is a mass-mailing worm. The worm arrives in an email message with the following characteristics:
From: (address may be forged)
Subject: Hi
Body:
Test =)
(random characters)
--
Test, yep.
Attachment: (random filename) 15,872 bytesexample:
frjujs.exe
When the attachment is run, the virus checks the system date. If the date is January 28, 2004 or later, the virus simply exits and does not propagate. Otherwise, the virus executes CALC.EXE and also copies itself as bbeagle.exe, and sets itself to load when you startup your machine. The worm uses your email address lists to send itself to others.
The virus spoofs the sender address (if you receive one, it's likely not sent by the address in the FROM: line).
You can tell if you're infected by going to Start--Search (or Find) and searching for a file called bbeagle.exe. If this file is on your computer, you're infected.
If you have not opened an attachment, you are not infected. If you get a mail message where the subject begins with "Virus Detected and Cleaned" the virus has already been removed from that message.
To remove the virus:
Some important notes about viruses
For more information about the W32/Bagle@MM virus, check http://vil.nai.com/vil/content/v_100965.htm
Follow these instructions to ensure your email continues to work after January 6, 2004.
On January 6, 2004, the ISU Office of Academic Information Technologies (AIT) will begin requiring updated network applications. This change is in response to security concerns and will provide a higher level of security for the ISU Extension network. Affected applications for Extension, in particular, are Scout and Eudora. You will need to update these applications on your computer now.
Please print these instructions before beginning.
To update your computer:
Update Scout: (only if you're prompted to do so)
Note: If you use Host Explorer, you will also need to update this program. You can do so by logging in as administrator, running Scout and updating Host Explorer.
If at any point you need further assistance, please contact the Extension IT Support Hotline at 515-294-1725.
Follow these instructions to ensure your email continues to work after January 6, 2004.
Note: If you have departmental IT staff, you may wish to contact them before following these instructions.
On January 6, 2004, the ISU Office of Academic Information Technologies (AIT) will begin requiring updated network applications. This change is in response to security concerns and will provide a higher level of security for the ISU network. Affected applications for Extension, in particular, are Scout and Eudora. You will need to update these applications on your computer now.
Please print these instructions before beginning.
Do NOT attempt to open your mail while logged on with the local administrator account.
To update your computer:
If Scout alerts you that a new version is available, follow these steps:
Note: If you use Host Explorer, you will also need to update this program. You can do so by logging in as administrator, running Scout and updating Host Explorer.
If at any point you need further assistance, please contact the Extension IT Support Hotline at 515-294-1725.