<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: UPS Tracking number trojan &#8211; new variant</title>
	<atom:link href="http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:53:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Jerry</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comment-17356</link>
		<dc:creator><![CDATA[Jerry]]></dc:creator>
		<pubDate>Tue, 10 Jan 2012 06:36:45 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99#comment-17356</guid>
		<description><![CDATA[Okay, so I have this virus and can&#039;t get rid of it so I&#039;m just going to recycle my hard drive tower and get a new one. Can this virus make its way into one&#039;s flat screen or printer? Do I need to get rid of those as well?

Big Spender]]></description>
		<content:encoded><![CDATA[<p>Okay, so I have this virus and can&#8217;t get rid of it so I&#8217;m just going to recycle my hard drive tower and get a new one. Can this virus make its way into one&#8217;s flat screen or printer? Do I need to get rid of those as well?</p>
<p>Big Spender</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: naishagirl</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comment-13236</link>
		<dc:creator><![CDATA[naishagirl]]></dc:creator>
		<pubDate>Tue, 09 Mar 2010 17:25:22 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99#comment-13236</guid>
		<description><![CDATA[No that doesn&#039;t work either, I&#039;ve tried it step by step. I&#039;ve tried so many things so far and nothing is working.]]></description>
		<content:encoded><![CDATA[<p>No that doesn&#8217;t work either, I&#8217;ve tried it step by step. I&#8217;ve tried so many things so far and nothing is working.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sammy</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comment-13082</link>
		<dc:creator><![CDATA[sammy]]></dc:creator>
		<pubDate>Fri, 15 Jan 2010 01:43:07 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99#comment-13082</guid>
		<description><![CDATA[I just got this email with an attachment found it bit suspicious so googled and find this website..Thanks for the info.... This is how my message looked

UPS Tracking Number 2657412.
UPS Manager Liza Fitch support@ups.com
Sent: Thu 1/14/2010 8:21 PM
To: myemail
UPS_INVOICE_NR76234.zip

Hello! 

The courier company was not able to deliver your parcel by your address.
Cause: Error in shipping address. 

You may pickup the parcel at our post office personaly!

Please attention!
The shipping label is attached to this e-mail. 
Please print this label to get this package at our post office.


Please do not reply to this e-mail, it is an unmonitored mailbox.]]></description>
		<content:encoded><![CDATA[<p>I just got this email with an attachment found it bit suspicious so googled and find this website..Thanks for the info&#8230;. This is how my message looked</p>
<p>UPS Tracking Number 2657412.<br />
UPS Manager Liza Fitch <a href="mailto:support@ups.com">support@ups.com</a><br />
Sent: Thu 1/14/2010 8:21 PM<br />
To: myemail<br />
UPS_INVOICE_NR76234.zip</p>
<p>Hello! </p>
<p>The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address. </p>
<p>You may pickup the parcel at our post office personaly!</p>
<p>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Please print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: match1</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comment-3993</link>
		<dc:creator><![CDATA[match1]]></dc:creator>
		<pubDate>Sat, 17 Jan 2009 21:55:30 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99#comment-3993</guid>
		<description><![CDATA[Nice news. Good side.]]></description>
		<content:encoded><![CDATA[<p>Nice news. Good side.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Rave</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comment-3559</link>
		<dc:creator><![CDATA[Dave Rave]]></dc:creator>
		<pubDate>Fri, 03 Oct 2008 21:44:31 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99#comment-3559</guid>
		<description><![CDATA[I received this one email, on to two computers.
both had AVG installed.
the first only showed the attachment, let me open it, the attached zip)
then I opened the inside doc file, wanting to watch AVG catch it and show me how good it is.

then, after it opened it, and infected my computer, &quot;after&quot; it infected my computer, it then said there was threat activity, showing me places that were suspect.

the second computer, downloaded the email, and netscape showed that AVG had already removed the attachment to the vault. no problems at all.

except the first computer is my notebook
the attached files are mainly .sys files
one of which I saw was hid something
i moved files to vault, rather than heal them
and now i have no keyboad, no touch pad, no usb for a mouse
and the ethernet jack is disabled as i would have turned it off, using my wireless

can&#039;t get to anything at all on it
and I AM SUCH A DILL. hates self ;-)]]></description>
		<content:encoded><![CDATA[<p>I received this one email, on to two computers.<br />
both had AVG installed.<br />
the first only showed the attachment, let me open it, the attached zip)<br />
then I opened the inside doc file, wanting to watch AVG catch it and show me how good it is.</p>
<p>then, after it opened it, and infected my computer, &#8220;after&#8221; it infected my computer, it then said there was threat activity, showing me places that were suspect.</p>
<p>the second computer, downloaded the email, and netscape showed that AVG had already removed the attachment to the vault. no problems at all.</p>
<p>except the first computer is my notebook<br />
the attached files are mainly .sys files<br />
one of which I saw was hid something<br />
i moved files to vault, rather than heal them<br />
and now i have no keyboad, no touch pad, no usb for a mouse<br />
and the ethernet jack is disabled as i would have turned it off, using my wireless</p>
<p>can&#8217;t get to anything at all on it<br />
and I AM SUCH A DILL. hates self <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doofus</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comment-3252</link>
		<dc:creator><![CDATA[Doofus]]></dc:creator>
		<pubDate>Wed, 20 Aug 2008 04:29:20 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99#comment-3252</guid>
		<description><![CDATA[I use OS/2 am I still vulnerable to this?]]></description>
		<content:encoded><![CDATA[<p>I use OS/2 am I still vulnerable to this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Turner</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comment-3135</link>
		<dc:creator><![CDATA[John Turner]]></dc:creator>
		<pubDate>Wed, 06 Aug 2008 20:31:53 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99#comment-3135</guid>
		<description><![CDATA[This is a viscous virus,

A friend has been infected by this and has caused major issues,

So far, from what has been understood, he accidently opened the file and did experiecend a system reboot shorlty after.

paniced, but once the system resumed he realised software was not running, windows os booted no problem, but all applcations failed to boot.

After some annoyance he tried rebooting this time, NTLDR was missing and required me to restore the boot sector with boot usb - lots of info on the internet is available for this!

after doing this booted the system ran norton, ran spybot and it all apperared to be okay.

gave him back his PC and now it reboots and loops, asking him to install some other antivirus software causing major issues, i need fix this soon as possible please help!]]></description>
		<content:encoded><![CDATA[<p>This is a viscous virus,</p>
<p>A friend has been infected by this and has caused major issues,</p>
<p>So far, from what has been understood, he accidently opened the file and did experiecend a system reboot shorlty after.</p>
<p>paniced, but once the system resumed he realised software was not running, windows os booted no problem, but all applcations failed to boot.</p>
<p>After some annoyance he tried rebooting this time, NTLDR was missing and required me to restore the boot sector with boot usb &#8211; lots of info on the internet is available for this!</p>
<p>after doing this booted the system ran norton, ran spybot and it all apperared to be okay.</p>
<p>gave him back his PC and now it reboots and loops, asking him to install some other antivirus software causing major issues, i need fix this soon as possible please help!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe McLean</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comment-3075</link>
		<dc:creator><![CDATA[Joe McLean]]></dc:creator>
		<pubDate>Tue, 29 Jul 2008 03:28:59 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99#comment-3075</guid>
		<description><![CDATA[A client was infected a week ago, so I imagine this was the varietion that was the payload.  I have followed the suggestions about how to remove the virus, but in his case, the virus also kept him from logging into Windows XP.  We removed his hard drive and ran it as a slave on two other computers.  On Tuesday when AVG was not rated as detecting the virus, it detected two Trojans,  but did not fix the log in problem.  

We scanned the HD as a slave on Wednesday with Trojan Remover which supposedly had worked for another computer, and on Friday with AVG which was supposed to detect the virus at that point.  We still were not able to login to Windows.  I finally moved the data to another computer, but my client would still like to fix the problem without reformatting.  Some posts on other websites suggest a damaged userinit.exe file would cause this problem.  Has anyone else seen this problem.]]></description>
		<content:encoded><![CDATA[<p>A client was infected a week ago, so I imagine this was the varietion that was the payload.  I have followed the suggestions about how to remove the virus, but in his case, the virus also kept him from logging into Windows XP.  We removed his hard drive and ran it as a slave on two other computers.  On Tuesday when AVG was not rated as detecting the virus, it detected two Trojans,  but did not fix the log in problem.  </p>
<p>We scanned the HD as a slave on Wednesday with Trojan Remover which supposedly had worked for another computer, and on Friday with AVG which was supposed to detect the virus at that point.  We still were not able to login to Windows.  I finally moved the data to another computer, but my client would still like to fix the problem without reformatting.  Some posts on other websites suggest a damaged userinit.exe file would cause this problem.  Has anyone else seen this problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam Vero</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comment-3059</link>
		<dc:creator><![CDATA[Adam Vero]]></dc:creator>
		<pubDate>Fri, 25 Jul 2008 14:13:55 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99#comment-3059</guid>
		<description><![CDATA[Lots more information here about the latest variation which claims to be from customs (or US customs in some cases):
http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/
Further  links in that post to previous versions of this malware with MD5 hashes for comparison.]]></description>
		<content:encoded><![CDATA[<p>Lots more information here about the latest variation which claims to be from customs (or US customs in some cases):<br />
<a href="http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/" rel="nofollow">http://veroblog.wordpress.com/2008/07/24/ups_invoice-email-trojan-variant-claims-to-be-from-customs-service/</a><br />
Further  links in that post to previous versions of this malware with MD5 hashes for comparison.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DH</title>
		<link>http://blog.mxlab.eu/2008/07/21/ups-tracking-number-trojan-new-variant/#comment-3050</link>
		<dc:creator><![CDATA[DH]]></dc:creator>
		<pubDate>Thu, 24 Jul 2008 18:16:19 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=99#comment-3050</guid>
		<description><![CDATA[Stupider users.
I&#039;ve been blocking/quarantining all executable &amp; compressed files in emails for several years -- 8 years since any malware has hit my network.  I recommend all admins do the same.  Some users may complain initially, but it saves the company money &amp; productivity in the long run.]]></description>
		<content:encoded><![CDATA[<p>Stupider users.<br />
I&#8217;ve been blocking/quarantining all executable &amp; compressed files in emails for several years &#8212; 8 years since any malware has hit my network.  I recommend all admins do the same.  Some users may complain initially, but it saves the company money &amp; productivity in the long run.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

