<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-4517116396504406307</atom:id><lastBuildDate>Wed, 19 Oct 2011 13:01:40 +0000</lastBuildDate><category>X.Win32/Zbot.M.nw</category><category>X.Win32/Oficla.T1</category><category>X.Virus.HIDDENEXT/Worm.tikt</category><category>X.W32.kryptik.bredo</category><category>X.W32.Zbot12.1.pak</category><category>X.Contract.PW/1110b</category><category>X.W32/Zbot.fees.08_09</category><category>X.FedEx.7631233</category><category>X.Trojan.Crypt.FKM.Gen</category><category>malware</category><category>X.Trojan-Spy.Win32.Agent</category><category>X.TrojanSpy:ups_Zbot</category><category>X.W32/troj.sriz/10.1</category><category>X.Trojan.Dropper.Gnup.d</category><category>X.JS.Redirect.CV</category><category>X.W32/OC-based.nuke.Aust</category><category>X.PW.exe</category><category>Fake UPS notice</category><category>X.Mal/Bredo-A5</category><category>X.Troj.Password-protec.bil</category><category>X.Win32/Cutwail.genC</category><category>X.Trojan.Win32.Goldun.int</category><category>X.W32\UPS.Invo-Zip</category><category>X.Trojan.Dropper.Gnup</category><category>X.Worm.W32.AutoRun.fees</category><category>X.W32/MalwareOC-based</category><category>X.Troj/In-Zip.a</category><category>spam</category><category>X.Win32/Bredolab.X</category><category>X.W32.Tibs.IT.pak</category><category>X.Trojan-Spy.W32.Zbot.WU.8/28</category><category>email</category><category>X.W32\zip-dobleextensionETIX</category><category>X.Win32/AutoRun.sTate</category><category>X.Mal/Bredo-A08a</category><category>X.Trojan.Virantix.C</category><category>X.Virus.HIDEXT/Worm.UpS</category><category>X.Win32/Bredolab.s1</category><category>fraud</category><category>X.Zbotb.0817ndg</category><category>X.W32/Autorun.MFAworm</category><category>X.Trojan.Spy.ZBot.kab</category><category>X.W32/troj.PW9/29</category><category>X.Trojan.Hijacker.start</category><category>X.Trojan.Dropper.Gnup.e</category><category>X.W32.Kryptik.GDT</category><category>X.Troj/Agent-JUC</category><category>X.Win32/Bredolab.t8</category><category>X.W32\Mal/EncPk-CZ</category><category>X.	Troj/Bckdr-QSL</category><category>X.W32\troj.click</category><category>X.W32.Fed.warn</category><category>X.Troj.Win32.Bredolab.drr</category><category>X.Trojan.Spy.ZBot.JFG</category><category>X.Win32/Kryptik.ACN.br</category><category>X.Trojan.Win32.FraudPack.bnk</category><category>X.W32/Banker.DWDR</category><category>X.Password-protected-EXE</category><category>X.W32/Generic.CNTR.zip</category><category>X.W32.troj.ts</category><category>X.Win32/Cutwail.W</category><category>X.W32/Zbot.BOH</category><category>X.Mal/Bredo-A08c</category><category>X.W32/Bredolab_B/Bb</category><category>X.Troj/Invo-Zip.fraud</category><category>Win32.Worm.McMaggot.B</category><category>X.W32/Generic.zip.stmt</category><category>X.W32/Agent_LGE_tr_intsall</category><category>X.W32\Agent-HNY</category><category>X.W32/troj.rprt.22</category><category>X.TROJ.Variant.Kates.2</category><category>X.W32/Dloadr.MAD</category><category>X.Trojan.Zbot_tr.num</category><category>X.Troj/BredoZp-B</category><category>X.W32/Agent_LGE_tr_open_d</category><category>X.Troj/Invo-Zip.etk</category><category>X.Mal/Bredo-J11b</category><category>X.W32/Generic.zip_statem</category><category>X.W32/troj.sriz.bl</category><category>X.Trojan-Spy:W32/Zbot.upsn</category><category>X.W32/troj.docGEN</category><category>X.Troj/Invo-Zip.fdx</category><category>X.W32/Rbot.uua</category><category>X.W32/Heuristic-10_20</category><category>X.Troj/Invo-Zip_kei</category><category>X.Airmail.POC4</category><category>X.Win32/Zbot.M.post2</category><category>X.Win32.Worm.McMaggot.A</category><category>X.Trojan.Win32.FraudPack.track</category><category>X.Win32/Emold.e-tix</category><category>X.W32/troj.9-29-fee</category><category>X.W32/troj.law</category><category>X.W32.Worm.Autorun.OD</category><category>X.Win32/Zbot.M.jj</category><category>X.W32/troj.Etix</category><category>X.W32/troj.rprt.23</category><category>X.W32/Heuristic300_wrldpay</category><category>X.W32.Bredolab.AN</category><category>X.Mal/Bredo-A02a</category><category>X.Trojan.Dldr.iBill</category><category>X.Mal/WaledPak.ax</category><category>X.W32.kryptik.hpqb</category><category>X.Trojan.Hijacker.Vidrar</category><category>X.el.Troj/Invo-Zip</category><category>X.W32/Heuristic-300.legis</category><category>UPS virus</category><category>X.Generic Malware.a zip</category><category>X.troj.passprotect.09</category><category>X.FakeAlert012810</category><category>X.W32.Mal/EncPk-MZ</category><category>X.Spy.ZBot.JFG</category><category>X.W32/troj.foto</category><category>X.W32/Mytob-AD</category><category>new malware</category><category>X.Troj/Invo-Zip.parcel</category><category>X.W32/Malware_OC_germn</category><category>X.Troj.FakeAlert.APY</category><category>X.W32/PackWaledac.B</category><category>X.W32.Zbot.deu</category><category>TrojanSpy.ZBot.AVA</category><category>X.W32.Kryptik.928</category><category>X.W32.Bredolab.apr1</category><category>X.Mal/Bredo-J10c</category><category>X.W32.troj.ob.OH.b</category><category>X.W32\Troj/Agent-HPK</category><category>X.Win32.Inject.gen</category><category>X.Troj/Invo-Zip_Ke</category><category>X.Trojan.Win32.Pakes.lio</category><category>X.Sus/Behav-1021.v2</category><category>X.Airmail.POC6</category><category>X.Mal/Bredo-A31b</category><category>X.Win32.AutoRun.sgv</category><category>X.Trojan.Dropper.Gnup.b</category><category>X.Trojan.Win32.Pakes.lin</category><category>X.W32/Mal/EncPk-CZ</category><category>X.Virus.HIDDENEXT/Worm.DET</category><category>X.W32.PX.pakc</category><category>X.W32/Trojan-Gypikon-based.BA</category><category>X.W32.HEURISTIC-Key</category><category>X.W32/Heuristic-300.reprt</category><category>X.Trojan.Fakealert.pass</category><category>W32.GenPac.8</category><category>X.Troj/Agent-_int_sus</category><category>X.W32/Zbot.BZI.ups</category><category>X.Sus/Behav-102</category><category>virus</category><category>X.W32/Zbot.BBU2</category><category>X.Trojan.Dropper.Gnup.c</category><category>X.Win32/Zbot.M.post</category><category>X.W32\Laposte.ZBot</category><category>X.W32\AirmailTrackPOC5</category><category>X.W32.Kryptik.102309</category><category>X.Troj/Virtum-Gen</category><category>X.W32/troj.push.leg</category><category>X.Mal/FakeAV-BW.1.1</category><category>X.VirTool:Win32/Obfuscator.CT</category><category>X.W32/AutoRun-Foto</category><category>X.Troj/Invo-Zip_ke2</category><category>X.W32/troj.tube</category><category>zbot</category><category>X.Win32/Spy.Zbot.VM1</category><category>X.Mal/EncPk-FS</category><category>X.W32/Dloadr.MAD3</category><category>X.w32/Mal.ENPk-westun</category><category>X.W32.Mal/EncPk-HZ</category><category>X.Win32/DelfInject.gen</category><category>X.Trojan.Kobcka.GZ</category><category>X.UPSTroj.mal.ix</category><category>X.Bredolab.Gen.2a</category><category>X.Win32.Bredolab.lx</category><category>X.W32.zbot.FH</category><category>X.Win32.Bredolab.ft</category><category>X.W32\troj.click2</category><category>X.Airmail.POC8</category><category>X.W32/Mal/EncPk-CZ9.12</category><category>fake eticket</category><category>X.W32/UPS.12/18</category><category>X.Win32.Invo</category><category>X.WaledPak-A</category><category>X.W32.Bredolab.FA</category><category>delta scam</category><category>X.Win32/Kryptik.AVJb</category><category>X.Win32.Oficla-AB.uld</category><category>W32.W32.SillyFDC</category><category>X.Mal/BredoPk-B</category><category>X.Kryptik.DQK</category><category>W32/troj.jkr</category><category>X.Mal/BredoPk-Bx</category><category>UPS trojan</category><category>X.Trojan.Crypt.XPACK.ec</category><category>X.Trojan.Dropper.Genup</category><category>fake av</category><category>X.Troj.Crypt.XPACK.Gen5</category><category>X.Win32:Oliga</category><category>X.W32/Malware.FWZJ.delt</category><category>X.Passprotected-08</category><category>X.BckDR.dhl.hter</category><category>X.W32\Troj/Invo-Zip</category><category>X.W32/Bredol_ric</category><category>security</category><category>X.Html.JS.915</category><category>Troj/BredoZp-I.dhl_a</category><category>W32.trojZbot.genB.</category><category>X.Win32/Oficla.IE</category><category>X.W32/delta.troj</category><category>ecard virus</category><category>X.Mal/Bredo-J10b</category><category>TR/Dldr.iBill.BR</category><category>X.Win32/Vundo.JN</category><category>X.Troj/In-Zip.dl</category><category>X.W32/Eldorado.lett</category><category>X.Troj/Invo-Zip.poste</category><category>X.W32/Heur.Eldorado.con_trct</category><category>X.Win32/Emold.gen C</category><category>X.W32\HIDDENEXT/Worm.Gen</category><category>X.W32/Dloadr.MAD2</category><category>X.Mal/Bredo-J10a</category><category>X.Mal/BredoPk-C</category><category>Win32/Zbot.genR</category><category>X.W32.Auraax</category><category>scam</category><category>X.W32/FakeAV.AM_b.</category><category>X.W32/MalwareOC-based.nuke</category><category>X.Win32/Zbot.J</category><category>X.Paypal.actx.a</category><category>X.W32.zbot.packed.gen.y</category><category>X.Mal/Bredo-A</category><category>X.Troj/Invo-Zip.trax</category><category>X.Trojan.Spy.Goldun.ecrd</category><category>X.W32.troj.acct.D</category><category>X.Mal/EncPk-CZ.8/28</category><category>X.Trojan.Spy.ZBot.kab.b</category><category>X.W32/FakeAlert</category><category>X.W32/troj.rprt.22.B</category><category>X.Virus.HIDDENEXT/Worm.st_tran</category><category>X.Mal/EncPk-feez</category><category>X.INSt.troj</category><category>appriver</category><category>Win32.Small.aglf</category><category>X.W32\IPLOGS.Zbot</category><category>X.W32.trojo.htm.a</category><category>X.W32.dhl.12.20</category><category>X.Win32.Crypt.mv</category><category>Bredo</category><category>X.W32/Agent.pass.protect</category><category>X.Mal/BredoPk-Bg</category><category>X.Win32/Bredolab.H</category><category>X.Win32.Invo.b</category><category>X.Troj.Win32.Zbot.cntrcts</category><category>X.W32\sriz.bl3</category><category>X.W32/Trojan.Spy.XYB</category><category>X.Trojan.Spy.Delf.eT</category><category>X.W32/troj.10/21St</category><category>ecard</category><category>delta virus</category><category>X.W32.downloader.gen2</category><category>X.W32.trojan.unknown1</category><category>X.Win32.Invo.c</category><category>X.W32/Goldun.RW.spy</category><category>X.Troj.BckDR.DHLver</category><category>X.W32/Bredolab.2a</category><category>X.Win32/Zbot.gen_Rb</category><category>X.Airmail/meta.POC3</category><category>X.Troj/Agent-wrldp</category><category>X.Mal/EncPk-CZ</category><category>X.W32/troj.OB.FH</category><category>X.W32/Metastopper.POC0</category><category>X.Trojan.Dropper.Delphi.Gen</category><category>ticketvirus</category><category>X.W32/troj.pw</category><category>X.W32\Trojan.Crypt.EE</category><category>X.W32/Heuristic.1_10</category><category>X.Win32/Cutwail.gen B</category><category>X.Bredolab.gen.v</category><category>X.Trojan.Win32.Agent.ak</category><category>X.Troj/Agent-HUV.lg</category><category>X.W32\Mal/EncPk-ES</category><category>X.W32/Heuristic-book</category><category>X.W32.Oficla-A1020</category><category>X.Win32/Zbot.gen_Ra</category><category>X.Mal/EncPk-PS</category><category>X.Troj_BredoZp-H1</category><category>W32/FakeAlert.IGU tr</category><category>X.Crypt.XPACK</category><category>X.Win32/Bredolab.G</category><category>X.Win32/Emold.gen_keys</category><category>X.W32/troj.instruct</category><category>X.W32/Malware.ix</category><category>X.mal/Bredolab.ocf</category><category>X.Mal/EncPk_eca</category><category>X.TrojanUPSpy:Win32/Zbot</category><category>X.Mal/BredoPk-Bf</category><category>X.W32/Heuristic_Eldorado</category><category>X.Trojan.Spy.Goldun.NDU</category><title>AppRiver Malware Watch</title><description>AppRiver's Email-borne Malware Updates</description><link>http://zerohour.appriver.com/</link><managingEditor>noreply@blogger.com (...phread)</managingEditor><generator>Blogger</generator><openSearch:totalResults>284</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/AppriverMalwareWatch" /><feedburner:info uri="apprivermalwarewatch" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-71750711220834729</guid><pubDate>Wed, 19 Oct 2011 12:55:00 +0000</pubDate><atom:updated>2011-10-19T06:01:40.695-07:00</atom:updated><title>X.Var.Kazy.1018</title><description>&lt;div&gt;Subject:&lt;strong&gt;Track your parcel No565810&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;Attachment: &lt;strong&gt;Post_Label_N0#75347&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;AVs: &lt;strong&gt;Bit, Comm, F-P, F-S, GD, K7, nP,So 8/42 (19.0%)&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;&lt;/strong&gt; &lt;/div&gt;&lt;div&gt;Body:&lt;/div&gt;&lt;div&gt;Dear customer.&lt;br /&gt;Your package has been sent to your address.&lt;br /&gt;Please find a post label attached which contains a track number of your package.&lt;br /&gt;You can find out an exact date of the delivery with the help of the track number.&lt;br /&gt;Thank you.&lt;br /&gt;DHL Customer.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-71750711220834729?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/kXJ_byZC8sQ" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/kXJ_byZC8sQ/xvarkazy1018.html</link><author>noreply@blogger.com (Troy Gill)</author><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2011/10/xvarkazy1018.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-3308977994206926646</guid><pubDate>Thu, 15 Sep 2011 14:12:00 +0000</pubDate><atom:updated>2011-09-15T07:22:35.133-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">virus</category><category domain="http://www.blogger.com/atom/ns#">appriver</category><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">fake av</category><title>X.Troj/FakeAV-ENL.ac</title><description>&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-d2nQjPz0st8/TnIH77oHeKI/AAAAAAAAAnU/9UqBG0F_bmE/s1600/achvirus.png"&gt;&lt;img style="margin: 0px auto 10px; width: 400px; height: 133px; text-align: center; display: block; cursor: pointer;" id="BLOGGER_PHOTO_ID_5652589208503023778" alt="" src="http://3.bp.blogspot.com/-d2nQjPz0st8/TnIH77oHeKI/AAAAAAAAAnU/9UqBG0F_bmE/s400/achvirus.png" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Subject: ACH Payment 53036341 Failed &lt;/span&gt;&lt;/div&gt;&lt;div style="font-weight: bold;"&gt;Attachment: report_1509.pdf.zip&lt;/div&gt;&lt;div&gt;&lt;span style="font-weight: bold;"&gt;AV: 13/44 (29.5%)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;&lt;span style="font-weight: bold;"&gt;Body:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: georgia;"&gt;The ACH transaction (ID: 95216329), recently sent from your bank account (by you or any other person), was rejected by the Electronic Payments Association.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: georgia;"&gt;###############################################&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: georgia;"&gt;Canceled transaction&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: georgia;"&gt;Transaction ID: 95216329&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: georgia;"&gt;Reason of rejection See details in the report below&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: georgia;"&gt;Transaction Report report_1509.pdf.zip (ZIP archive, Adobe PDF)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: georgia;"&gt;###############################################&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: georgia;"&gt;13450 Sunrise Valley Drive, Suite 100 Herndon, VA 20171 (703) 561-1100&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: georgia;"&gt;2011 NACHA - The Electronic Payments Association&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-3308977994206926646?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/s8NCVzaEaq0" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/s8NCVzaEaq0/xtrojfakeav-enlac.html</link><author>noreply@blogger.com (Troy Gill)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-d2nQjPz0st8/TnIH77oHeKI/AAAAAAAAAnU/9UqBG0F_bmE/s72-c/achvirus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2011/09/xtrojfakeav-enlac.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-2277391990029865961</guid><pubDate>Wed, 27 Jul 2011 13:24:00 +0000</pubDate><atom:updated>2011-07-27T06:38:07.573-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">virus</category><category domain="http://www.blogger.com/atom/ns#">appriver</category><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">email</category><category domain="http://www.blogger.com/atom/ns#">scam</category><category domain="http://www.blogger.com/atom/ns#">security</category><title>X.Mal/BredoZp-B_1</title><description>&lt;div&gt;&lt;div&gt;&lt;img style="margin: 0px auto 10px; width: 400px; height: 138px; text-align: center; display: block; cursor: pointer;" id="BLOGGER_PHOTO_ID_5634024407658625090" border="0" alt="" src="http://3.bp.blogspot.com/-dl_UqnDcoes/TjATWTJfeEI/AAAAAAAAAnM/hmHj_s7tG7s/s400/hotel.png" /&gt;Subject: Hotel The ST. Regis Monarch Beach made wrong transaction(hotel name varys)&lt;div&gt;&lt;div&gt;Attachment: RefundForm129.zip (45K)&lt;/div&gt;&lt;div&gt;AVs: 3/43 (7%) So, TrM, TrM(HC)&lt;br /&gt;&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-2277391990029865961?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/XEtgNsepP0M" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/XEtgNsepP0M/xmalbredozp-b1.html</link><author>noreply@blogger.com (Troy Gill)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-dl_UqnDcoes/TjATWTJfeEI/AAAAAAAAAnM/hmHj_s7tG7s/s72-c/hotel.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2011/07/xmalbredozp-b1.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-5966163090757450981</guid><pubDate>Fri, 01 Apr 2011 13:41:00 +0000</pubDate><atom:updated>2011-04-01T06:44:16.426-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.Bredolab.apr1</category><title>X.W32.Bredolab.apr1</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-UcheHjBnI0E/TZXWqJjbLkI/AAAAAAAABaQ/MOaCf9egadk/s1600/virus.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 232px;" src="http://3.bp.blogspot.com/-UcheHjBnI0E/TZXWqJjbLkI/AAAAAAAABaQ/MOaCf9egadk/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5590610532057689666" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Subject:    &lt;b&gt;Post Express Branch. Get the parcel NR 79792&lt;/b&gt;  (random number)&lt;br /&gt;Attachment:   &lt;span style="font-weight: bold;"&gt;Invoice_Copy_IN585.zip&lt;/span&gt;&lt;br /&gt;AVs:  &lt;span style="font-weight: bold;"&gt; 5/41 (12.2%)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Body:&lt;br /&gt;&lt;br /&gt;&lt;tt class="letterText"&gt;Good afternoon.&lt;br /&gt;&lt;br /&gt;Post notification. No.58479&lt;br /&gt;&lt;br /&gt;The company could not deliver your package to your address.&lt;br /&gt;Your package has been returned to the Post Express office.&lt;br /&gt;The reason of the return is "Error in the delivery address"&lt;br /&gt;&lt;br /&gt;Please attention!&lt;br /&gt;Attached to the letter mailing label contains the details of the package delivery.&lt;br /&gt;Please print out the invoice copy attached and collect the package at our office&lt;br /&gt;&lt;br /&gt;Thank you for attention.&lt;br /&gt;Post Express.&lt;br /&gt;&lt;/tt&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-5966163090757450981?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/FIwyZPrSXoU" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/FIwyZPrSXoU/xw32bredolabapr1.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-UcheHjBnI0E/TZXWqJjbLkI/AAAAAAAABaQ/MOaCf9egadk/s72-c/virus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2011/04/xw32bredolabapr1.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-7609447312966082232</guid><pubDate>Thu, 10 Mar 2011 16:09:00 +0000</pubDate><atom:updated>2011-03-10T08:15:27.972-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.trojo.htm.a</category><title>X.W32.trojo.htm.a</title><description>&lt;a href="http://2.bp.blogspot.com/-_ruQ6DS7yu4/TXj5FvcREHI/AAAAAAAAAm4/nuw8cW0iuRY/s1600/growphish.png"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 235px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5582485615155417202" border="0" alt="" src="http://2.bp.blogspot.com/-_ruQ6DS7yu4/TXj5FvcREHI/AAAAAAAAAm4/nuw8cW0iuRY/s400/growphish.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Subject: &lt;strong&gt;Dear Grow Financial customer,&lt;/strong&gt;&lt;br /&gt;Attachment: &lt;strong&gt;GrowFinancialFCU_Account_Restore_Form.pdf.zip&lt;/strong&gt;&lt;br /&gt;AVs:&lt;strong&gt; 0/43&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Body:&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;We recently reviewed your account, and we are suspecting that your Grow Financial Internet Banking account may have been accessed from an unauthorized computer..&lt;br /&gt;&lt;br /&gt;This may be due to changes in your IP address or location. Protecting the security of your account and of the Grow Financial Bank network is our primary concern.&lt;br /&gt;&lt;br /&gt;We are asking you to immediately login and report any unauthorized withdrawals, and check your account profile to make sure no changes have been made.&lt;br /&gt;&lt;br /&gt;To protect your account please follow the instructions below:&lt;br /&gt;&lt;br /&gt;* DO NOT SHARE YOUR PASSWORD WITH OTHER USERS&lt;br /&gt;&lt;br /&gt;* LOG OFF AFTER USING YOUR ONLINE ACCOUNT&lt;br /&gt;&lt;br /&gt;We attached to this email a confirmation form to update your details, please download and extract it .&lt;br /&gt;&lt;br /&gt;Submitting this form you will restore your Grow Financial account. NOTE: The form needs to be opened in a modern browser which has javascript enabled (ex: Internet Explorer, Firefox ,Netscape)&lt;br /&gt;&lt;br /&gt;We apologize for any inconvenience this may cause, and appreciate your support in helping us maintaining the integrity of the entire Grow Financial Bank system.&lt;br /&gt;&lt;br /&gt;Thank you.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-7609447312966082232?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/NLWt9hDcySw" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/NLWt9hDcySw/xw32trojohtma.html</link><author>noreply@blogger.com (Troy Gill)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-_ruQ6DS7yu4/TXj5FvcREHI/AAAAAAAAAm4/nuw8cW0iuRY/s72-c/growphish.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2011/03/xw32trojohtma.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-7369377971269383416</guid><pubDate>Tue, 01 Mar 2011 17:28:00 +0000</pubDate><atom:updated>2011-03-01T09:32:49.595-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.zbot.packed.gen.y</category><title>X.W32.zbot.packed.gen.y</title><description>&lt;a href="http://1.bp.blogspot.com/-c8Skgb3J3NQ/TW0trDSRtpI/AAAAAAAAAmw/ezRD610T_GQ/s1600/ups.png"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 103px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5579165731021502098" border="0" alt="" src="http://1.bp.blogspot.com/-c8Skgb3J3NQ/TW0trDSRtpI/AAAAAAAAAmw/ezRD610T_GQ/s400/ups.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Subject: &lt;th style="VERTICAL-ALIGN: top"&gt;&lt;/th&gt;&lt;td style="WHITE-SPACE: normal"&gt;&lt;b&gt;UPS Delivery NoticeID1645651&lt;th style="VERTICAL-ALIGN: top"&gt;&lt;/th&gt;&lt;td style="WHITE-SPACE: normal"&gt;&lt;/td&gt;&lt;/b&gt;&lt;/td&gt;&lt;/div&gt;&lt;div&gt;Attachment: &lt;strong&gt;ups-prt-copy-Invoice-3710398-74119628.zip (137 KB)&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;AVs: &lt;span class="blackthick"&gt;&lt;strong&gt;&lt;span id="detected"  style="color:red;"&gt;3&lt;/span&gt;/ &lt;span id="status-total"&gt;42 (7.1%) Dr, Mc, So&lt;/span&gt;&lt;/strong&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;Body:&lt;/div&gt;&lt;br /&gt;&lt;div&gt;ï»¿ Hello!&lt;br /&gt;Unfortunately we failed to deliver the postal package you have sent in time because the recipient's address is erroneous.&lt;br /&gt;Please print out the shipment label attached and collect the package at our office.&lt;br /&gt;Thank you,&lt;br /&gt;UPS Express &lt;span  nbsp="" style="color:#fffffe;"&gt;Brown's dedication to service began when he personally experienced the impact and importance of the Ronald McDonald House(RMH). Brown's son, Dallas, was born with sever&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-7369377971269383416?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/-KJS3Ql_k5M" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/-KJS3Ql_k5M/xw32zbotpackedgeny.html</link><author>noreply@blogger.com (Troy Gill)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-c8Skgb3J3NQ/TW0trDSRtpI/AAAAAAAAAmw/ezRD610T_GQ/s72-c/ups.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2011/03/xw32zbotpackedgeny.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-5372159664912981268</guid><pubDate>Fri, 18 Feb 2011 16:17:00 +0000</pubDate><atom:updated>2011-02-18T08:22:05.845-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.PX.pakc</category><title>X.W32.PX.pakc</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-Ih3pnW4-0Fo/TV6cox-jFCI/AAAAAAAABaI/QRpKh_gm1r8/s1600/virus.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 193px;" src="http://3.bp.blogspot.com/-Ih3pnW4-0Fo/TV6cox-jFCI/AAAAAAAABaI/QRpKh_gm1r8/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5575065613155636258" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Subject:   &lt;b&gt;Post Express! Package is available for pickup! NR8907456  &lt;/b&gt; (random number)&lt;br /&gt;&lt;b&gt;                 &lt;/b&gt;&lt;b&gt;Post Express! Get the parcel NR5459323&lt;/b&gt;  (random number)&lt;br /&gt;                &lt;b&gt;Post Express Service! Error in the delivery address! NR5269&lt;/b&gt; (random number)&lt;br /&gt;Attachment: &lt;span style="font-weight: bold;"&gt;Post_Express_Label_SN.59075.zip&lt;/span&gt;&lt;br /&gt;                      &lt;span style="font-weight: bold;"&gt;Post_Express_Label_RES.0677.zip&lt;/span&gt;&lt;br /&gt;                      &lt;span style="font-weight: bold;"&gt;Post_Express_Label_IVN83867.zip&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Body:&lt;br /&gt;&lt;br /&gt;Good afternoon&lt;br /&gt;&lt;br /&gt;Email notification ID 64354510&lt;br /&gt;&lt;br /&gt;Your package has been returned to the Post Express office.&lt;br /&gt;&lt;br /&gt;The reason of the return is "Incorrect delivery address of the package"&lt;br /&gt;&lt;br /&gt;Important message!&lt;br /&gt;Attached to the letter mailing label contains the details of the package delivery.&lt;br /&gt;You have to print mailing label, and come in the Post Express office in order to receive the packages.&lt;br /&gt;&lt;br /&gt;Thank you for using our services.&lt;br /&gt;Post Express Support&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-5372159664912981268?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/FpRxVA6m2HI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/FpRxVA6m2HI/xw32pxpakc.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-Ih3pnW4-0Fo/TV6cox-jFCI/AAAAAAAABaI/QRpKh_gm1r8/s72-c/virus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2011/02/xw32pxpakc.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-8299777966394349546</guid><pubDate>Thu, 20 Jan 2011 14:37:00 +0000</pubDate><atom:updated>2011-01-20T06:41:52.647-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.downloader.gen2</category><title>X.W32.downloader.gen2</title><description>&lt;a href="http://3.bp.blogspot.com/_qUhp3IwflnM/TThJRKTk3sI/AAAAAAAAAmg/Swj7Ieg-h9g/s1600/gtg.png"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 435px; DISPLAY: block; HEIGHT: 154px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5564277898789314242" border="0" alt="" src="http://3.bp.blogspot.com/_qUhp3IwflnM/TThJRKTk3sI/AAAAAAAAAmg/Swj7Ieg-h9g/s400/gtg.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Subject: &lt;strong&gt;happy day!&lt;br /&gt;&lt;/strong&gt;Attachment: &lt;strong&gt;happyday.zip&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;Body:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;hope u like ~~~LOL&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_qUhp3IwflnM/TThJBN6pE2I/AAAAAAAAAmY/F73Qyb3IUUM/s1600/happyday.png"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-8299777966394349546?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/fsa1mdX-Uyc" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/fsa1mdX-Uyc/xw32downloadergen2.html</link><author>noreply@blogger.com (Troy Gill)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_qUhp3IwflnM/TThJRKTk3sI/AAAAAAAAAmg/Swj7Ieg-h9g/s72-c/gtg.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2011/01/xw32downloadergen2.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-7051611305142525504</guid><pubDate>Mon, 20 Dec 2010 14:54:00 +0000</pubDate><atom:updated>2010-12-20T06:57:08.674-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.dhl.12.20</category><title>X.W32.dhl.12.20</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ktAVO86cbXQ/TQ9unOUgGZI/AAAAAAAABZ4/uv8shnkj50I/s1600/virus.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 119px;" src="http://2.bp.blogspot.com/_ktAVO86cbXQ/TQ9unOUgGZI/AAAAAAAABZ4/uv8shnkj50I/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5552778485709150610" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Subject: &lt;/span&gt;   &lt;span class="click" title=""&gt;"&gt;DHL International Services&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Attachment:&lt;/span&gt;   SNPcopy_122010.zip&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Body:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;Dear Sir/Madam,&lt;br /&gt;&lt;br /&gt;Your package has been returned to the DHL office. The reason of the return is - Error in the delivery address&lt;br /&gt;&lt;br /&gt;Attached to the letter mailing label contains the details of the package delivery. You have to print mailing label, and come in the office in order to receive the packages.&lt;br /&gt;&lt;br /&gt;Thank you for attention.&lt;br /&gt;&lt;br /&gt;DHL&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; &lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-7051611305142525504?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/8XRkA1g_Xbo" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/8XRkA1g_Xbo/xw32dhl1220.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_ktAVO86cbXQ/TQ9unOUgGZI/AAAAAAAABZ4/uv8shnkj50I/s72-c/virus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/12/xw32dhl1220.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-6973763876325393676</guid><pubDate>Wed, 08 Dec 2010 17:05:00 +0000</pubDate><atom:updated>2010-12-08T09:09:07.281-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.Paypal.actx.a</category><title>X.Paypal.actx.a</title><description>&lt;a href="http://3.bp.blogspot.com/_qUhp3IwflnM/TP-6-RIobxI/AAAAAAAAAmE/3vJ7voetwXA/s1600/paypal.png"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 221px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5548358844858003218" border="0" alt="" src="http://3.bp.blogspot.com/_qUhp3IwflnM/TP-6-RIobxI/AAAAAAAAAmE/3vJ7voetwXA/s400/paypal.png" /&gt;&lt;/a&gt; Subject: Your Account Has Been Limited !&lt;br /&gt;Attachment: PayPal.com_Account_Confirmation_Form.pdf.zip&lt;br /&gt;AVs: 0/43 0%&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-6973763876325393676?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/Ef2CHbY67p8" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/Ef2CHbY67p8/xpaypalactxa.html</link><author>noreply@blogger.com (Troy Gill)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_qUhp3IwflnM/TP-6-RIobxI/AAAAAAAAAmE/3vJ7voetwXA/s72-c/paypal.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/12/xpaypalactxa.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-9015949314004800305</guid><pubDate>Wed, 01 Dec 2010 21:23:00 +0000</pubDate><atom:updated>2010-12-01T13:43:36.262-08:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.Zbot12.1.pak</category><title>X.W32.Zbot12.1.pak</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ktAVO86cbXQ/TPbBeICmRqI/AAAAAAAABZw/JdeoHAHkjDI/s1600/virus.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 269px;" src="http://3.bp.blogspot.com/_ktAVO86cbXQ/TPbBeICmRqI/AAAAAAAABZw/JdeoHAHkjDI/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5545832714451961506" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Subject:&lt;/span&gt;   &lt;b&gt;DHL Delivery Services,&lt;/b&gt; &lt;b&gt;DHL Parcel Message, &lt;/b&gt;&lt;b&gt;DHL Notification Message&lt;/b&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Attachment:&lt;/span&gt;   &lt;span style="font-weight: bold;"&gt;238000.zip, 681229.zip, 56037.zip, 981677.zip&lt;/span&gt; ...&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Body:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;                                     &lt;span&gt;Dear Customer!&lt;/span&gt;          &lt;br /&gt;                                     &lt;br /&gt;&lt;p&gt;We were not able to deliver your package to your address!&lt;br /&gt;     Please pick up your package in local DHL office.&lt;br /&gt;&lt;br /&gt;     &lt;b&gt;Attention!&lt;/b&gt;&lt;br /&gt;     The post label is attached to this e-mail.&lt;br /&gt;     We kindly ask you to print it and take it to the post office to pick up the package.&lt;br /&gt;     Thank you!              &lt;/p&gt;   &lt;span&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;DHL EXPRESS - good for business&lt;/strong&gt;&lt;/p&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-9015949314004800305?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/PNNLVSv2BFo" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/PNNLVSv2BFo/xw32zbot121pak.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_ktAVO86cbXQ/TPbBeICmRqI/AAAAAAAABZw/JdeoHAHkjDI/s72-c/virus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/12/xw32zbot121pak.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-1084034565068170212</guid><pubDate>Thu, 28 Oct 2010 14:43:00 +0000</pubDate><atom:updated>2010-10-28T07:46:37.945-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.Zbot.deu</category><title>X.W32.Zbot.deu</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ktAVO86cbXQ/TMmMxEPyHLI/AAAAAAAABZo/cjvS-r3vvfw/s1600/virus.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 149px;" src="http://2.bp.blogspot.com/_ktAVO86cbXQ/TMmMxEPyHLI/AAAAAAAABZo/cjvS-r3vvfw/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5533108391782784178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Subject:   &lt;b&gt;Ich weiß nicht, wie ich es sagen, aber ich habe vor langer&lt;br /&gt;&lt;/b&gt;Attachment: &lt;b&gt;  Bild.zip&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Body:&lt;b&gt;&lt;br /&gt;&lt;br /&gt;&lt;/b&gt;&lt;tt class="letterText"&gt;Hallo Man,&lt;br /&gt;&lt;br /&gt;Ich weiЯ nicht, wie ich es sagen, aber ich habe vor langer Zeit zu euch  senden einige Fotos tryed, aber ich habe gedacht, dass Sie nicht  interessiert sind, mich zu sehen.&lt;br /&gt;Aber jetzt werde ich Ihnen die Fotos in der Anlage.&lt;br /&gt;Laden Sie die Bilder und extrahieren sie, ich bin sicher, dass Sie sie mцgen. Das Passwort ist: 123456&lt;br /&gt;&lt;br /&gt;Machen Sie einen schцnen Tag.&lt;br /&gt;&lt;/tt&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-1084034565068170212?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/qsV0e2oOwTI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/qsV0e2oOwTI/xw32zbotdeu.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_ktAVO86cbXQ/TMmMxEPyHLI/AAAAAAAABZo/cjvS-r3vvfw/s72-c/virus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/10/xw32zbotdeu.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-575421831912305682</guid><pubDate>Tue, 26 Oct 2010 14:05:00 +0000</pubDate><atom:updated>2010-10-26T07:10:20.226-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.kryptik.hpqb</category><title>X.W32.kryptik.hpqb</title><description>&lt;strong&gt;Subject:&lt;/strong&gt; UPS Invoice copy N47204&lt;br /&gt;&lt;strong&gt;Attachment:&lt;/strong&gt; UPS_document_ID38967.zip&lt;br /&gt;&lt;strong&gt;AVs:&lt;/strong&gt; (18.2% detection rate)&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;Body:&lt;br /&gt;&lt;/strong&gt;(see image)&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_qUhp3IwflnM/TMbgx9rHJYI/AAAAAAAAAl8/iawwyCwyYnU/s1600/ups.png"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 252px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5532356341244831106" border="0" alt="" src="http://3.bp.blogspot.com/_qUhp3IwflnM/TMbgx9rHJYI/AAAAAAAAAl8/iawwyCwyYnU/s400/ups.png" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-575421831912305682?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/gAr980eV5lk" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/gAr980eV5lk/xw32kryptikhpqb.html</link><author>noreply@blogger.com (Troy Gill)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_qUhp3IwflnM/TMbgx9rHJYI/AAAAAAAAAl8/iawwyCwyYnU/s72-c/ups.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/10/xw32kryptikhpqb.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-7851974760216550930</guid><pubDate>Wed, 20 Oct 2010 18:49:00 +0000</pubDate><atom:updated>2010-10-20T11:51:14.960-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.Oficla-A1020</category><title>X.W32.Oficla-A1020</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ktAVO86cbXQ/TL86GexrKCI/AAAAAAAABZg/xHd_bUacHBQ/s1600/virus.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 277px;" src="http://2.bp.blogspot.com/_ktAVO86cbXQ/TL86GexrKCI/AAAAAAAABZg/xHd_bUacHBQ/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5530202750449297442" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Subject:    &lt;b&gt;Your package is available for pickup.ID25391 (random number)&lt;/b&gt;&lt;br /&gt;Attachment:    &lt;span style="font-weight: bold;"&gt;UPS_Label_NR7753.zip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Body:&lt;br /&gt;&lt;br /&gt;Hello&lt;br /&gt;&lt;br /&gt;Your parcel has arrived at the post office on October 18.&lt;br /&gt;Our Driver was unable to deliver the parcel to your address.&lt;br /&gt;To receive a parcel you must go to the nearest UPS office and show your mailing label.&lt;br /&gt;You need to print mailing label, and show it in UPS office to receive the parcel.&lt;br /&gt;&lt;br /&gt;Thank you for your attention.&lt;br /&gt;UPS Global Services.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-7851974760216550930?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/GJbWK7z0tZY" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/GJbWK7z0tZY/xw32oficla-a1020.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_ktAVO86cbXQ/TL86GexrKCI/AAAAAAAABZg/xHd_bUacHBQ/s72-c/virus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/10/xw32oficla-a1020.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-8372913780685032128</guid><pubDate>Thu, 14 Oct 2010 13:20:00 +0000</pubDate><atom:updated>2010-10-14T06:25:14.711-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32/Bredolab.2a</category><title>X.W32/Bredolab.2a</title><description>&lt;a href="http://1.bp.blogspot.com/_qUhp3IwflnM/TLcD-7rE6FI/AAAAAAAAAl0/kGNCey9ckA0/s1600/upsbredo.png"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 148px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5527891447325714514" border="0" alt="" src="http://1.bp.blogspot.com/_qUhp3IwflnM/TLcD-7rE6FI/AAAAAAAAAl0/kGNCey9ckA0/s400/upsbredo.png" /&gt;&lt;/a&gt;Subject: &lt;strong&gt;UPS Online Service. Error delivery address number 7114&lt;/strong&gt;&lt;br /&gt;Attachment:&lt;strong&gt; dode.jpg&lt;/strong&gt;&lt;br /&gt;AVs:10 /43 (23.3%) Au, Cat, Cl, eS, F-P, Jia, K7, PcT, So, TheH&lt;br /&gt;&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Body: &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Dear client&lt;br /&gt;&lt;/strong&gt;&lt;strong&gt;Your parcel has arrived at the post office on October 12. Our Driver was unable to deliver the parcel to your address.To receive a parcel you must go to the nearest UPS office and show your mailing label.Mailing label is attached to this letter.&lt;br /&gt;&lt;/strong&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;You need to print mailing label, and show it in UPS office to receive the parcel.&lt;br /&gt;&lt;/strong&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Thank you for your attention.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;UPS Global Services.&lt;/strong&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-8372913780685032128?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/Ab3i06nn7Rg" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/Ab3i06nn7Rg/xw32bredolab2a.html</link><author>noreply@blogger.com (Troy Gill)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_qUhp3IwflnM/TLcD-7rE6FI/AAAAAAAAAl0/kGNCey9ckA0/s72-c/upsbredo.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/10/xw32bredolab2a.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-6475115687196223661</guid><pubDate>Mon, 04 Oct 2010 13:53:00 +0000</pubDate><atom:updated>2010-10-04T06:57:13.983-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">virus</category><category domain="http://www.blogger.com/atom/ns#">appriver</category><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">X.Win32/Oficla.T1</category><title>X.Win32/Oficla.T1</title><description>&lt;a href="http://1.bp.blogspot.com/_qUhp3IwflnM/TKnc0JWdUnI/AAAAAAAAAls/TmTAMP1Nhdc/s1600/ups.png"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 206px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5524189206368047730" border="0" alt="" src="http://1.bp.blogspot.com/_qUhp3IwflnM/TKnc0JWdUnI/AAAAAAAAAls/TmTAMP1Nhdc/s400/ups.png" /&gt;&lt;/a&gt; Subject:&lt;strong&gt;USPS Delivery Problem NR5170282&lt;/strong&gt;&lt;br /&gt;Attachmant: &lt;strong&gt;USPSLabel.zip&lt;/strong&gt;&lt;br /&gt;AV's: &lt;strong&gt;2/ 43 (4.7%&lt;/strong&gt;)&lt;br /&gt;&lt;br /&gt;Body:&lt;br /&gt;*Uses image as shown above&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-6475115687196223661?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/1Q2jrmVys6I" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/1Q2jrmVys6I/xwin32oficlat1.html</link><author>noreply@blogger.com (Troy Gill)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_qUhp3IwflnM/TKnc0JWdUnI/AAAAAAAAAls/TmTAMP1Nhdc/s72-c/ups.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/10/xwin32oficlat1.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-3373736496878949194</guid><pubDate>Tue, 28 Sep 2010 16:43:00 +0000</pubDate><atom:updated>2010-09-28T09:44:41.263-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.Kryptik.928</category><title>X.W32.Kryptik.928</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ktAVO86cbXQ/TKIbb3ZjbII/AAAAAAAABZY/rjBLLoVRFL8/s1600/virus.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 252px;" src="http://3.bp.blogspot.com/_ktAVO86cbXQ/TKIbb3ZjbII/AAAAAAAABZY/rjBLLoVRFL8/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5522006258651196546" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Subject:   &lt;b&gt;Approved meeting minues&lt;/b&gt;&lt;br /&gt;Attachment:  &lt;span style="font-weight: bold;"&gt; Approved.zip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;body:&lt;br /&gt;&lt;br /&gt;&lt;tt class="letterText"&gt;Good Morning Everyone,&lt;br /&gt;Here are the approved September 28, 2010 meeting minutes.&lt;br /&gt; &lt;/tt&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-3373736496878949194?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/39K2A6z3hoM" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/39K2A6z3hoM/xw32kryptik928.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_ktAVO86cbXQ/TKIbb3ZjbII/AAAAAAAABZY/rjBLLoVRFL8/s72-c/virus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/09/xw32kryptik928.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-5429223361617182459</guid><pubDate>Fri, 24 Sep 2010 13:12:00 +0000</pubDate><atom:updated>2010-09-24T06:23:50.370-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.Win32.Oficla-AB.uld</category><title>X.Win32.Oficla-AB.uld</title><description>&lt;a href="http://2.bp.blogspot.com/_qUhp3IwflnM/TJymQcW-ceI/AAAAAAAAAlk/FSXETZhfSH8/s1600/usps.png"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 227px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5520470044670063074" border="0" alt="" src="http://2.bp.blogspot.com/_qUhp3IwflnM/TJymQcW-ceI/AAAAAAAAAlk/FSXETZhfSH8/s400/usps.png" /&gt;&lt;/a&gt; Subject: &lt;strong&gt;USPS Delivery Problem NR368058&lt;/strong&gt;&lt;br /&gt;Attachment: &lt;strong&gt;USPSLabelDoc.zip (23 KB)&lt;/strong&gt;&lt;br /&gt;AVs: Result: &lt;strong&gt;5/ 42 (11.9%) CL, GD, NOD, PA, PR&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Message Body (uses a .jpg instead of text)&lt;/strong&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://4.bp.blogspot.com/_qUhp3IwflnM/TJymM_-yVuI/AAAAAAAAAlc/mXkykq3HdS8/s1600/im1.jpg"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 102px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5520469985512806114" border="0" alt="" src="http://4.bp.blogspot.com/_qUhp3IwflnM/TJymM_-yVuI/AAAAAAAAAlc/mXkykq3HdS8/s400/im1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-5429223361617182459?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/zbh9uLp9PyA" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/zbh9uLp9PyA/xwin32oficla-abuld.html</link><author>noreply@blogger.com (Troy Gill)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_qUhp3IwflnM/TJymQcW-ceI/AAAAAAAAAlk/FSXETZhfSH8/s72-c/usps.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/09/xwin32oficla-abuld.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-6868681231343994566</guid><pubDate>Wed, 15 Sep 2010 16:44:00 +0000</pubDate><atom:updated>2010-09-15T09:46:05.980-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.Html.JS.915</category><title>X.Html.JS.915</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ktAVO86cbXQ/TJD4RpxqIAI/AAAAAAAABZQ/WbF3M77ASv0/s1600/virus.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 275px; height: 400px;" src="http://3.bp.blogspot.com/_ktAVO86cbXQ/TJD4RpxqIAI/AAAAAAAABZQ/WbF3M77ASv0/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5517182525684457474" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Subject:   &lt;span style="font-weight: bold;"&gt;Labels and such&lt;/span&gt;&lt;br /&gt;Attachment:   &lt;span style="font-weight: bold;"&gt; label.html&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Body:&lt;br /&gt;&lt;br /&gt;Labels and such Hey complet&lt;br /&gt;&lt;br /&gt;Payment has been made and attached are the  labels.&lt;br /&gt;Thanks a ton man, very cool!&lt;br /&gt;Can't wait to get  em.&lt;br /&gt;&lt;br /&gt;Laura&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Your  payment for $375.00 USD to complet@talb.com has been sent.&lt;br /&gt;&lt;br /&gt;It may take a  few moments for this transaction to appear in the Recent Activity list on your  Account Overview.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Payment details&lt;br /&gt;Amount: $375.00  USD&lt;br /&gt;Transaction Date: Sep 15, 2010&lt;br /&gt;Transaction ID:  8U7617815K399153U&lt;br /&gt;&lt;br /&gt;Subject: You've got money!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-6868681231343994566?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/nImD2OXQe-g" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/nImD2OXQe-g/xhtmljs915.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_ktAVO86cbXQ/TJD4RpxqIAI/AAAAAAAABZQ/WbF3M77ASv0/s72-c/virus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/09/xhtmljs915.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-8236833457925226944</guid><pubDate>Wed, 01 Sep 2010 13:16:00 +0000</pubDate><atom:updated>2010-09-01T06:20:51.551-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.Win32/Oficla.IE</category><title>X.Win32/Oficla.IE</title><description>&lt;a href="http://2.bp.blogspot.com/_qUhp3IwflnM/TH5Su8OybYI/AAAAAAAAAk8/Qr_lD9uuhxI/s1600/dhl.png"&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 400px; DISPLAY: block; HEIGHT: 150px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5511933960343678338" border="0" alt="" src="http://2.bp.blogspot.com/_qUhp3IwflnM/TH5Su8OybYI/AAAAAAAAAk8/Qr_lD9uuhxI/s400/dhl.png" /&gt;&lt;/a&gt; Subject: &lt;strong&gt;DHL Services. Get your parcel number 3948&lt;/strong&gt;&lt;br /&gt;Attachment:&lt;strong&gt; di cosol.jpg (23 KB)&lt;br /&gt;&lt;/strong&gt;&lt;div&gt;AVs: &lt;strong&gt;15/ 43 (34.9%)&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;&lt;/strong&gt; &lt;/div&gt;&lt;div&gt;Body:&lt;/div&gt;&lt;div&gt;&lt;strong&gt;Dear customer.&lt;br /&gt;We were not able to deliver your package to your address.&lt;br /&gt;&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;Reason: Error in delivery address.&lt;br /&gt;&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;Attention!&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;Get your parcel in your local post office.The postal label is attached to this e-mail.We kindly ask you to print it and take it to the post office to pick up the package. &lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;&lt;/strong&gt; &lt;/div&gt;&lt;div&gt;&lt;strong&gt;Thank you!&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;DHL International GmbH.&lt;/strong&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-8236833457925226944?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/lw0VQFWeEa4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/lw0VQFWeEa4/xwin32oficlaie.html</link><author>noreply@blogger.com (Troy Gill)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_qUhp3IwflnM/TH5Su8OybYI/AAAAAAAAAk8/Qr_lD9uuhxI/s72-c/dhl.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/09/xwin32oficlaie.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-567654010816898784</guid><pubDate>Mon, 23 Aug 2010 21:51:00 +0000</pubDate><atom:updated>2010-08-23T14:54:14.565-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.Mal/FakeAV-BW.1.1</category><title>X.Mal/FakeAV-BW.1.1</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ktAVO86cbXQ/THLt_TqnevI/AAAAAAAABZA/DNp86-LGpjw/s1600/virus.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 276px;" src="http://1.bp.blogspot.com/_ktAVO86cbXQ/THLt_TqnevI/AAAAAAAABZA/DNp86-LGpjw/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5508726966094101234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Subject:   &lt;b&gt;Fedex Invoice copy N9956225 (random number)&lt;/b&gt;&lt;br /&gt;Attachment:   &lt;span style="font-weight: bold;"&gt;FEDEXInvoiceEE744573OP.zip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Body:&lt;br /&gt;[image]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-567654010816898784?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/GAb_-OKHWBQ" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/GAb_-OKHWBQ/xmalfakeav-bw11.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_ktAVO86cbXQ/THLt_TqnevI/AAAAAAAABZA/DNp86-LGpjw/s72-c/virus.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/08/xmalfakeav-bw11.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-861259300506586901</guid><pubDate>Thu, 19 Aug 2010 16:03:00 +0000</pubDate><atom:updated>2010-08-19T09:05:21.364-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.JS.Redirect.CV</category><title>X.JS.Redirect.CV</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ktAVO86cbXQ/TG1WOWmdf5I/AAAAAAAABY4/mp4WZ6x-Yw8/s1600/resume1.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 292px;" src="http://2.bp.blogspot.com/_ktAVO86cbXQ/TG1WOWmdf5I/AAAAAAAABY4/mp4WZ6x-Yw8/s400/resume1.png" alt="" id="BLOGGER_PHOTO_ID_5507152723929038738" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Subject:  &lt;span style="font-weight: bold;"&gt; Resume&lt;/span&gt;&lt;br /&gt;Attachment:   &lt;span style="font-weight: bold;"&gt;CV.html&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Body:&lt;br /&gt;&lt;br /&gt;please find attached my cv&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-861259300506586901?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/N1UaZd_qSjo" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/N1UaZd_qSjo/xjsredirectcv.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_ktAVO86cbXQ/TG1WOWmdf5I/AAAAAAAABY4/mp4WZ6x-Yw8/s72-c/resume1.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/08/xjsredirectcv.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-2382214423683039034</guid><pubDate>Thu, 19 Aug 2010 16:01:00 +0000</pubDate><atom:updated>2010-08-19T09:03:52.044-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.Kryptik.GDT</category><title>X.W32.Kryptik.GDT</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ktAVO86cbXQ/TG1V34uYM0I/AAAAAAAABYw/4NDlj1dWN2A/s1600/virus.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 150px;" src="http://3.bp.blogspot.com/_ktAVO86cbXQ/TG1V34uYM0I/AAAAAAAABYw/4NDlj1dWN2A/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5507152337952060226" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Subject:   &lt;b&gt;Rejected ACH transaction, please review the transaction report&lt;/b&gt;&lt;br /&gt;Attachment:   &lt;span style="font-weight: bold;"&gt;ACH_0889388_REP.zip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;body:&lt;br /&gt;&lt;br /&gt;&lt;tt class="letterText"&gt;Dear bank account holder,&lt;br /&gt;&lt;br /&gt;The ACH transaction, recently initiated from your bank account (by you  or any other person), was rejected by the Electronic Payments  Association. Please Find Attached Transaction Report&lt;br /&gt;&lt;br /&gt;------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Electronic Payments Association Manager&lt;/tt&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-2382214423683039034?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/ibxuyo5opv4" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/ibxuyo5opv4/xw32kryptikgdt.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_ktAVO86cbXQ/TG1V34uYM0I/AAAAAAAABYw/4NDlj1dWN2A/s72-c/virus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/08/xw32kryptikgdt.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-3583868693622338525</guid><pubDate>Tue, 17 Aug 2010 14:13:00 +0000</pubDate><atom:updated>2010-08-17T07:17:24.774-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.W32.zbot.FH</category><title>X.W32.zbot.FH</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ktAVO86cbXQ/TGqZhy5msbI/AAAAAAAABYo/xuoTYtvNpcE/s1600/virus.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 318px;" src="http://2.bp.blogspot.com/_ktAVO86cbXQ/TGqZhy5msbI/AAAAAAAABYo/xuoTYtvNpcE/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5506382300291969458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Subject:   &lt;span style="font-weight: bold;"&gt;Good Music&lt;/span&gt;&lt;br /&gt;Attachment:   &lt;span style="font-weight: bold;"&gt;Second chord sounds in world's longest lasting concert - Yahoo! News.zip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Body:&lt;br /&gt;&lt;br /&gt;It has a beat, you can dance to it – I’d give it an eight.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;************************************************************************&lt;br /&gt;This e-mail and any of its attachments may contain Exelon Corporation&lt;br /&gt;proprietary information, which is privileged, confidential, or subject&lt;br /&gt;to copyright belonging to the Exelon Corporation family of Companies.&lt;br /&gt;This e-mail is intended solely for the use of the individual or entity&lt;br /&gt;to which it is addressed. If you are not the intended recipient of this&lt;br /&gt;e-mail, you are hereby notified that any dissemination, distribution,&lt;br /&gt;copying, or action taken in relation to the contents of and attachments&lt;br /&gt;to this e-mail is strictly prohibited and may be unlawful. If you have&lt;br /&gt;received this e-mail in error, please notify the sender immediately and&lt;br /&gt;permanently delete the original and any copy of this e-mail and any&lt;br /&gt;printout. Thank You.&lt;br /&gt;************************************************************************&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-3583868693622338525?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/SMCIxdUNTKU" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/SMCIxdUNTKU/xw32zbotfh.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_ktAVO86cbXQ/TGqZhy5msbI/AAAAAAAABYo/xuoTYtvNpcE/s72-c/virus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/08/xw32zbotfh.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4517116396504406307.post-4026326033209135788</guid><pubDate>Tue, 17 Aug 2010 13:34:00 +0000</pubDate><atom:updated>2010-08-17T06:36:30.469-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">X.Zbotb.0817ndg</category><title>X.Zbotb.0817ndg</title><description>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ktAVO86cbXQ/TGqQRFGcfnI/AAAAAAAABYg/eInAgm5HhqU/s1600/virus.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 243px;" src="http://1.bp.blogspot.com/_ktAVO86cbXQ/TGqQRFGcfnI/AAAAAAAABYg/eInAgm5HhqU/s400/virus.png" alt="" id="BLOGGER_PHOTO_ID_5506372117515239026" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Subject:   &lt;b&gt;Tracking # and Invoice&lt;/b&gt;&lt;br /&gt;Attachment:   &lt;span style="font-weight: bold;"&gt;attach.zip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Body:&lt;br /&gt;&lt;br /&gt;&lt;tt class="letterText"&gt;CIRCUIT SPECIALISTS, INC.                                TRACK                                 Date-Tue, 17 Aug 2010  22:19:02 +0900   Ref# TRACK&lt;br /&gt;                                                                                           Time-15:35:42   Page    1&lt;br /&gt;Ship Date            Tue, 17 Aug 2010 22:19:02 +0900        THRU Tue, 17 Aug 2010 22:19:02 +0900&lt;br /&gt;&lt;br /&gt;The attached file is a copy of your invoice.  It is best viewed with&lt;br /&gt;notepad or some other text viewer that does not try to format the text.&lt;br /&gt;&lt;br /&gt;Date Shipped  Our Ref.   Your Ref.       Tracking #&lt;br /&gt;Tue, 17 Aug 2010 22:19:02 +0900          255596 NET 52777       1Z8771870342348672&lt;/tt&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/4517116396504406307-4026326033209135788?l=zerohour.appriver.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/AppriverMalwareWatch/~4/8IgngKQNxyI" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/AppriverMalwareWatch/~3/8IgngKQNxyI/xzbotb0817ndg.html</link><author>noreply@blogger.com (...phread)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_ktAVO86cbXQ/TGqQRFGcfnI/AAAAAAAABYg/eInAgm5HhqU/s72-c/virus.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://zerohour.appriver.com/2010/08/xzbotb0817ndg.html</feedburner:origLink></item></channel></rss>

