Subject: ALERT: Message from port-macppc was cleaned; File Bmqh.pif infected with
To: None <Antigen_Notification_List%FIRE@fordham.edu>
From: None <fire-smtp02.fire.fordham.edu/FIRE%FIRE@fordham.edu>
List: port-macppc
Date: 10/05/2002 06:11:53
Please refer to the Antigen Quarantine Area for more details.
INCIDENT
------------------------------------------------------------------------------------------------------------------------
Scan Time: 10/05/2002 06:11:48 AM
Detection: File Bmqh.pif infected with Win32/Klez.H.Worm (aka
W32/Klez.h@MM, Win32.Klez.H, I-Worm.Klez.h, W32/Klez.H@m, W32/Klez-H) virus
Disposition: Note has been cleaned
Quarantined: (Document link: Quarantine Area document)
CN=fire-smtp02.fire.fordham.edu/O=FIRE!!D:\Lotus\Domino\Data\A6QArea.NSF
Version: Antigen 6.0 SR3 (Build 607)
MESSAGE
------------------------------------------------------------------------------------------------------------------------
Message ID: 0038023D
Sender: port-macppc <port-macppc@netbsd.org>
Subject: A good tool
Recipients: BROOKES@FORDHAM.EDU
Routing:
SYNOPSIS
------------------------------------------------------------------------------------------------------------------------
HTML Message Body
(superscript: << Normal >>)
Status: OK
FILE ATTACHMENT 'Tribute[4].asp'
<< Normal >>
File size: 5626 bytes
Host type: STREAM
Compression: OFF
Attributes: PUBLIC READ-WRITE
File flags: 2
Created: 10/05/2002 06:11:45 AM
Modified: 10/05/2002 06:11:45 AM
Status: OK
FILE ATTACHMENT 'Bmqh.pif'
<< Win32/Klez.H.Worm (aka W32/Klez.h@MM, Win32.Klez.H, I-Worm.Klez.h, W32/Klez.H@m, W32/Klez-H) >>
File size: 89889 bytes
Host type: STREAM
Content type: Exe.Win32
Compression: OFF
Attributes: PUBLIC READ-WRITE
File flags: 2
Created: 10/05/2002 06:11:45 AM
Modified: 10/05/2002 06:11:45 AM
Status: Displaced
<< Bmqh.pif >>
Scanner: CA(InoculateIT) 23.57.513 [23.57.54] Win32/Klez.H.Worm
Scanner: NAI 4.1.60 [4.2.27] W32/Klez.h@MM
Scanner: CA(Vet) 10.53.1 [10.53.4140] Win32.Klez.H
Scanner: Kaspersky 4.0.273 [0.0.58796] I-Worm.Klez.h
Scanner: Norman 5.0.0 [5.0.0] W32/Klez.H@m
Scanner: Sophos 2.10.0 [3.61.0] W32/Klez-H