Did anyone else get this? I am hoping it is just a false positive. There didn't seem to be anything special in the header info (pasted below the message) and since I have my system set to delete all viruses I cannot get much more information about it.
Dana Millaway District Technology Coordinator Holdingford Public Schools -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: Tuesday, August 16, 2005 11:00 AM To: clamav-users@lists.clamav.net Subject: {Virus?} clamav-users Digest, Vol 11, Issue 15 Warning: This message has had one or more attachments removed Warning: (the entire message). Warning: Please read the "VirusWarning.txt" attachment(s) for more information. This is a message from the MailScanner E-Mail Virus Protection Service ---------------------------------------------------------------------- The original e-mail attachment "the entire message" was believed to be infected by a virus and has been replaced by this warning message. Due to limitations placed on us by the Regulation of Investigatory Powers Act 2000, we were unable to keep a copy of the infected attachment. Please ask the sender of the message to disinfect their original version and send you a clean copy. At Tue Aug 16 11:00:40 2005 the virus scanner said: msg-19493-25.txt contains Trojan.Downloader.FTP.Gen-4 -- Postmaster -------Header Information-------------------------------- Return-Path: <[EMAIL PROTECTED]> Received: from barracuda.mset.k12.mn.us ([174.0.24.5]) by www.holdingford.k12.mn.us (8.10.2-SOL3/8.10.2) with ESMTP id j7GG0Z200429 for <[EMAIL PROTECTED]>; Tue, 16 Aug 2005 11:00:35 -0500 X-ASG-Debug-ID: 1124207535-6611-12-0 X-Barracuda-URL: http://174.0.24.5:8000/cgi-bin/mark.cgi Received: from aj.catt.com (aj.catt.com [64.18.103.6]) by barracuda.mset.k12.mn.us (Barracuda Spam Firewall) with ESMTP id 6A8C76BB8 for <[EMAIL PROTECTED]>; Tue, 16 Aug 2005 11:00:32 -0500 (CDT) Received: from aj.catt.com (localhost [127.0.0.1]) by aj.catt.com (Postfix) with ESMTP id 171A516DDD3; Tue, 16 Aug 2005 12:00:10 -0400 (EDT) From: [EMAIL PROTECTED] X-ASG-Orig-Subj: clamav-users Digest, Vol 11, Issue 15 Subject: {Virus?} clamav-users Digest, Vol 11, Issue 15 To: clamav-users@lists.clamav.net Reply-To: clamav-users@lists.clamav.net MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 8bit X-BeenThere: clamav-users@lists.clamav.net X-Mailman-Version: 2.1.5 Precedence: list List-Id: ClamAV users ML <clamav-users.lists.clamav.net> List-Unsubscribe: <http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users>, <mailto:[EMAIL PROTECTED]> List-Post: <mailto:clamav-users@lists.clamav.net> List-Help: <mailto:[EMAIL PROTECTED]> List-Subscribe: <http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-users>, <mailto:[EMAIL PROTECTED]> Sender: [EMAIL PROTECTED] Errors-To: [EMAIL PROTECTED] Message-Id: <[EMAIL PROTECTED]> Date: Tue, 16 Aug 2005 12:00:10 -0400 (EDT) X-Virus-Scanned: by Barracuda Spam Firewall at mset.k12.mn.us X-Barracuda-Spam-Status: No, SCORE=0.2 using global scores of TAG_LEVEL=3.5 QUARANTINE_LEVEL=1000.0 KILL_LEVEL=9.0 tests=HTML_MESSAGE, NO_REAL_NAME X-Barracuda-Spam-Report: Code version 2.64, rules version 2.1.3375 Rule breakdown below pts rule name description ---- ---------------------- ------------------------------------------- 0.18 NO_REAL_NAME From: does not include a real name 0.01 HTML_MESSAGE BODY: HTML included in message X-ISD738-MailScanner-Information: Please contact the ISP for more information X-ISD738-MailScanner: Found to be infected X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on www.holdingford.k12.mn.us X-Spam-Level: X-Spam-Status: No, hits=0.7 required=6.0 tests=AWL,NO_REAL_NAME autolearn=no version=2.63 X-UIDL: h1S"!nAo!!o2+!!kG]!! Status: U _______________________________________________ http://lurker.clamav.net/list/clamav-users.html