Quarantined email attachment warning

NAV for Microsoft Exchange-SPAEXCH01 <[email protected]> Thu, 6 Jun 2002 22:10:58 -0400
Newsgroups gmane.os.netbsd.ports.mips
Message-ID <750CC28A4CEBD5119AE200508B2C7DDA3CCCC8@SPAEXCH01>
Dear Sir or Mam,
The file attachment you sent to Byerly, Wendy\Inbox is not an authorized
file type or it contains a virus that can not be removed from the file.

If you do not understand this message, please send an email to
[email protected].
Please do not reply to this email address.  It is not monitored or checked
at all.
Please note that currently we have noticed an increase in the detection of
the W32.KLEZ virus and a number of its variations.  Symantec Corporation has
a clean tool that has proven to be helpful to us. It may also help you.
It has an information page at:
http://securityresponse.symantec.com/avcenter/venc/data/
w32.klez.removal.tool.html
If you have not had the opportunity to read the W32.Klez Virus information,
please read this excerpt from the Symantec Web Page:

Email spoofing (Source:
http://securityresponse.symantec.com/avcenter/venc/data/[email protected]
)
Some variants of this worm use a technique known as spoofing. If so, the
worm randomly selects an address that it finds on an infected computer. It
uses this address as the From address that it uses when it performs its
mass-mailing routine. Numerous cases have been reported in which users of
uninfected computers received complaints that they sent an infected message
to someone else.

For example, Linda Anderson is using a computer that is infected with
W32.Klez.E@mm; Linda is not using an antivirus program or does not have
current virus definitions. When W32.Klez.gen@mm performs its emailing
routine, it finds the email address of Harold Logan. It inserts Harold's
email address into the From portion of an infected message that it then
sends to Janet Bishop. Janet then contacts Harold and complains that he sent
her an infected message, but when Harold scans his computer, Norton
AntiVirus does not find anything--as would be expected--because his computer
is not infected.

If you are using a current version of Norton AntiVirus and you have the most
recent virus definitions, and a full system scan with Norton AntiVirus set
to scan all files does not find anything, you can be confident that your
computer is not infected with this worm.



Sincerly,
The Information Technology Staff
Mid-South Management Company.
Crescent Media Group.

Recipient of the infected attachment:  Byerly, Wendy\Inbox
Subject of the message:  Questionnaire
One or more attachments were quarantined.
  Attachment src.exe was Quarantined for the following reasons:
    Virus UNAUTHORIZED FILE was found.
(unnamed) (application/ms-tnef, 2.9 KB) - not displayed