[an error occurred while processing this directive]
Spam detection software, running on the system "amantadine.ncsa.uiuc.edu", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
postmaster@ncsa.uiuc.edu for details.
Content preview: Warning: This message has had one or more attachments
removed Warning: (vmi-bugncsa.uiuc.edu..pif, accepted-password.zip).
Warning: Please read the "NCSA-Attachment-Warning.txt" attachment(s) for
more information. [...]
Content analysis details: (12.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
2.6 MSGID_OUTLOOK_INVALID Message-Id is fake (in Outlook Express format)
-2.6 BAYES_00 BODY: Bayesian spam probability is 0 to 1%
[score: 0.0000]
2.0 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP address
[71.107.177.225 listed in dnsbl.sorbs.net]
2.4 RCVD_IN_WHOIS_BOGONS RBL: CompleteWhois: sender on bogons IP block
[153.183.158.226 listed in combined-HIB.dnsiplists.completewhois.com]
1.9 RCVD_IN_NJABL_DUL RBL: NJABL: dialup sender did non-local SMTP
[71.107.177.225 listed in combined.njabl.org]
1.7 MSGID_DOLLARS Message-Id has pattern used in spam
1.9 RATWARE_MS_HASH Bulk email fingerprint (msgid ms hash) found
2.8 RATWARE_OUTLOOK_NONAME Bulk email fingerprint (Outlook no name)
found
The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.
--- Begin Message ---
- To: <vmi-bug@ncsa.uiuc.edu>
- Subject: {Virus?} delivery
- From: "Mail Delivery Subsystem" <postmaster@ncsa.uiuc.edu>
- Date: Thu, 20 Apr 2006 18:37:26 -0700
- Content-type: multipart/mixed; boundary="----=_NextPart_000_0356_84FA2940.B647B805"
Warning: This message has had one or more attachments removed Warning: (vmi-bugncsa.uiuc.edu..pif, accepted-password.zip). Warning: Please read the "NCSA-Attachment-Warning.txt" attachment(s) for more information.This is a message from the MailScanner E-Mail Virus Protection Service ---------------------------------------------------------------------- The original e-mail attachment "accepted-password.zip" was believed to be infected by a virus and has been replaced by this warning message. If you wish to receive a copy of the *infected* attachment, please e-mail the NCSA Help Desk (help@ncsa.uiuc.edu) and include this message with your request. Alternatively, you can call them at +1 217 244 0709 with the contents of this message on hand when you call. At Thu Apr 20 21:04:34 2006 the virus scanner said: ClamAV Module: accepted-password.zip was infected: Exploit.W32.MS05-039 Note to Help Desk: Look on the NCSA MailScanner (rimantadine) in /var/spool/quarantine/20060420 (message k3L24ANv016306). -- The NCSA Email guys
--- End Message ---