<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: UPS Tracking number trojan &#8211; another variant and Hallmark e-card</title>
	<atom:link href="http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Thu, 09 Feb 2012 14:53:11 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Mike</title>
		<link>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/#comment-3060</link>
		<dc:creator><![CDATA[Mike]]></dc:creator>
		<pubDate>Fri, 25 Jul 2008 16:26:45 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=114#comment-3060</guid>
		<description><![CDATA[A new variant seems to have appeared.  Got this to a users mailbox this morning.  Attachment was named E-ticket_N7399294.zip.  Inside the zip is a file &quot;E-ticket_N7399294_and_Invoice_for_N73992943442.exe&quot;

From: Tara Lloyd&quot; US Airways [mailto:okvwgh@bolderstaffing.com]
Sent: Friday, July 25, 2008 10:31 AM
To: [removed]
Subject: Online order for airplane ticket N182416


Hello,
Thank you for using our new service &quot;Buy airplane ticket Online&quot; on our website. Your account has been created:

Your login: [removed - was same as recipient&#039;s username]
Your password: pass5OB6

Your credit card has been charged for $456.08.
We would like to remind you that whenever you order tickets on our website you get a discount of 10%! Attached to this message is the purchase Invoice and the flight ticket. To use your ticket, simply print it on a color printed, and you are set to take off for the journey!

Kind regards,
Tara Lloyd
US Airways]]></description>
		<content:encoded><![CDATA[<p>A new variant seems to have appeared.  Got this to a users mailbox this morning.  Attachment was named E-ticket_N7399294.zip.  Inside the zip is a file &#8220;E-ticket_N7399294_and_Invoice_for_N73992943442.exe&#8221;</p>
<p>From: Tara Lloyd&#8221; US Airways [mailto:okvwgh@bolderstaffing.com]<br />
Sent: Friday, July 25, 2008 10:31 AM<br />
To: [removed]<br />
Subject: Online order for airplane ticket N182416</p>
<p>Hello,<br />
Thank you for using our new service &#8220;Buy airplane ticket Online&#8221; on our website. Your account has been created:</p>
<p>Your login: [removed - was same as recipient's username]<br />
Your password: pass5OB6</p>
<p>Your credit card has been charged for $456.08.<br />
We would like to remind you that whenever you order tickets on our website you get a discount of 10%! Attached to this message is the purchase Invoice and the flight ticket. To use your ticket, simply print it on a color printed, and you are set to take off for the journey!</p>
<p>Kind regards,<br />
Tara Lloyd<br />
US Airways</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian</title>
		<link>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/#comment-3048</link>
		<dc:creator><![CDATA[Brian]]></dc:creator>
		<pubDate>Thu, 24 Jul 2008 14:39:35 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=114#comment-3048</guid>
		<description><![CDATA[The version one of my users got tries to block running the SDFix.exe archive.  Renamed it to SDFix2.exe and it extracted.]]></description>
		<content:encoded><![CDATA[<p>The version one of my users got tries to block running the SDFix.exe archive.  Renamed it to SDFix2.exe and it extracted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Laurentio</title>
		<link>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/#comment-3046</link>
		<dc:creator><![CDATA[Laurentio]]></dc:creator>
		<pubDate>Thu, 24 Jul 2008 10:28:16 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=114#comment-3046</guid>
		<description><![CDATA[So far this is the only way to remove the UPS virus. Follow the given link and do as instructed to fix UPS virus.
http://support.bicester-computers.com/showthread.php?t=18]]></description>
		<content:encoded><![CDATA[<p>So far this is the only way to remove the UPS virus. Follow the given link and do as instructed to fix UPS virus.<br />
<a href="http://support.bicester-computers.com/showthread.php?t=18" rel="nofollow">http://support.bicester-computers.com/showthread.php?t=18</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mxlab</title>
		<link>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/#comment-3042</link>
		<dc:creator><![CDATA[mxlab]]></dc:creator>
		<pubDate>Thu, 24 Jul 2008 08:40:06 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=114#comment-3042</guid>
		<description><![CDATA[And there is already a new variant so it seems that the UPS trojan will keep on going for a while. Virus Total reports shows that 5 of the 35 engines detect the newer version.]]></description>
		<content:encoded><![CDATA[<p>And there is already a new variant so it seems that the UPS trojan will keep on going for a while. Virus Total reports shows that 5 of the 35 engines detect the newer version.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sparky Clarkey</title>
		<link>http://blog.mxlab.eu/2008/07/23/ups-tracking-number-trojan-another-variant-and-hallmark-ecard/#comment-3041</link>
		<dc:creator><![CDATA[Sparky Clarkey]]></dc:creator>
		<pubDate>Thu, 24 Jul 2008 08:12:33 +0000</pubDate>
		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=114#comment-3041</guid>
		<description><![CDATA[That is us just received another of these e-mails this morning on another computer.
It has got past our B.T. Business Virus checker this time although in the previous attempt it was detected and deleted.
United Parcel   UPS Tracking Number 7937399669 so it is still very active.
Bullguard did not detect the original attempt or even seems able to remove it so far. 

We have tried several products and followed instructions religiously to remove this virus but at the time of writing one computer is still are infected.]]></description>
		<content:encoded><![CDATA[<p>That is us just received another of these e-mails this morning on another computer.<br />
It has got past our B.T. Business Virus checker this time although in the previous attempt it was detected and deleted.<br />
United Parcel   UPS Tracking Number 7937399669 so it is still very active.<br />
Bullguard did not detect the original attempt or even seems able to remove it so far. </p>
<p>We have tried several products and followed instructions religiously to remove this virus but at the time of writing one computer is still are infected.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

