<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: New Bredolab trojan variants in DHL and UPS tracking emails</title>
	<atom:link href="http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Sat, 31 Jul 2010 13:59:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Porter Cable Parts</title>
		<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/#comment-13225</link>
		<dc:creator>Porter Cable Parts</dc:creator>
		<pubDate>Sat, 06 Mar 2010 22:20:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=731#comment-13225</guid>
		<description>I got the same email today its much worse with google mail i think now</description>
		<content:encoded><![CDATA[<p>I got the same email today its much worse with google mail i think now</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bernie</title>
		<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/#comment-13221</link>
		<dc:creator>Bernie</dc:creator>
		<pubDate>Fri, 05 Mar 2010 18:18:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=731#comment-13221</guid>
		<description>Looks like I&#039;ve just received a variant:
its attachment is &quot;UPS-invoice-2756.zip&quot;
it was sent in a spam mail from a server with IP 123.235.226.7 which is registered for &quot;China Unicom Shandong Province Network&quot;</description>
		<content:encoded><![CDATA[<p>Looks like I&#8217;ve just received a variant:<br />
its attachment is &#8220;UPS-invoice-2756.zip&#8221;<br />
it was sent in a spam mail from a server with IP 123.235.226.7 which is registered for &#8220;China Unicom Shandong Province Network&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Loostra</title>
		<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/#comment-13162</link>
		<dc:creator>Loostra</dc:creator>
		<pubDate>Thu, 04 Feb 2010 01:11:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=731#comment-13162</guid>
		<description>Nice find, I have fixed mine thanks to these guys:
http://support.bicestercomputers.co.uk/showthread.php?t=18&amp;page=19</description>
		<content:encoded><![CDATA[<p>Nice find, I have fixed mine thanks to these guys:<br />
<a href="http://support.bicestercomputers.co.uk/showthread.php?t=18&amp;page=19" rel="nofollow">http://support.bicestercomputers.co.uk/showthread.php?t=18&amp;page=19</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amber</title>
		<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/#comment-13144</link>
		<dc:creator>amber</dc:creator>
		<pubDate>Fri, 29 Jan 2010 03:53:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=731#comment-13144</guid>
		<description>I received 3 of these emails, 1 was the DHL and the other two the UPS I also wonder how one of them ended up in my email as i was not the recipient. Luckily Norton anti virus picked it up before it had a chance to do any damage! PHEW!!</description>
		<content:encoded><![CDATA[<p>I received 3 of these emails, 1 was the DHL and the other two the UPS I also wonder how one of them ended up in my email as i was not the recipient. Luckily Norton anti virus picked it up before it had a chance to do any damage! PHEW!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul Smith</title>
		<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/#comment-13142</link>
		<dc:creator>Paul Smith</dc:creator>
		<pubDate>Thu, 28 Jan 2010 13:51:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=731#comment-13142</guid>
		<description>I have also got that same e-mail. Fortunately it was detected  by Antivirus. Thanks for the info.</description>
		<content:encoded><![CDATA[<p>I have also got that same e-mail. Fortunately it was detected  by Antivirus. Thanks for the info.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guy</title>
		<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/#comment-13105</link>
		<dc:creator>Guy</dc:creator>
		<pubDate>Sat, 23 Jan 2010 06:34:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=731#comment-13105</guid>
		<description>23 january 2010- I got that same email saying it was from DHL posting services. Norton Antivirus detected it in my Yahoo mail . It seems to bee very recent; i didn,t found a lot on internet about it at this time... Thanks for this post, with all these informations!!!</description>
		<content:encoded><![CDATA[<p>23 january 2010- I got that same email saying it was from DHL posting services. Norton Antivirus detected it in my Yahoo mail . It seems to bee very recent; i didn,t found a lot on internet about it at this time&#8230; Thanks for this post, with all these informations!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wok3</title>
		<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/#comment-13103</link>
		<dc:creator>wok3</dc:creator>
		<pubDate>Fri, 22 Jan 2010 01:12:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=731#comment-13103</guid>
		<description>I got the same mail 2 days ago (19 jan 2010).

My antivirus didn&#039;t said anything but WinZIp popped up an alert saying that the file was not an archive or that it was corrupted and you should download it again (yeah sure!!) , so i haven&#039;t even seen the .exe file INSIDE the .zip file.

Even though i&#039;d like to know if there&#039;s a version of this email/virus in wich you don&#039;t even need to run the .exe compressed into the .zip file but through some sort of exploit get folled by the &quot;couldn&#039;t open file&quot; by WinZIp and still be infected.

Sophos antivirus detected the virus inside the .zip file but after deleting it it didn&#039;t found it anywhere else.

Anyone has info about this?

thanks, wok3</description>
		<content:encoded><![CDATA[<p>I got the same mail 2 days ago (19 jan 2010).</p>
<p>My antivirus didn&#8217;t said anything but WinZIp popped up an alert saying that the file was not an archive or that it was corrupted and you should download it again (yeah sure!!) , so i haven&#8217;t even seen the .exe file INSIDE the .zip file.</p>
<p>Even though i&#8217;d like to know if there&#8217;s a version of this email/virus in wich you don&#8217;t even need to run the .exe compressed into the .zip file but through some sort of exploit get folled by the &#8220;couldn&#8217;t open file&#8221; by WinZIp and still be infected.</p>
<p>Sophos antivirus detected the virus inside the .zip file but after deleting it it didn&#8217;t found it anywhere else.</p>
<p>Anyone has info about this?</p>
<p>thanks, wok3</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dhaval Malte</title>
		<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/#comment-13102</link>
		<dc:creator>Dhaval Malte</dc:creator>
		<pubDate>Thu, 21 Jan 2010 15:19:58 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=731#comment-13102</guid>
		<description>I got same mail today. Even I wonder how did that mail land in my mailbox, when the ID given is not mine.

Any ways my Microsoft Security Essentials caught it even before I could open that attachment.</description>
		<content:encoded><![CDATA[<p>I got same mail today. Even I wonder how did that mail land in my mailbox, when the ID given is not mine.</p>
<p>Any ways my Microsoft Security Essentials caught it even before I could open that attachment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jayne</title>
		<link>http://blog.mxlab.eu/2010/01/19/new-bredolab-trojan-variants-in-dhl-and-ups-tracking-emails/#comment-13100</link>
		<dc:creator>Jayne</dc:creator>
		<pubDate>Thu, 21 Jan 2010 08:34:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mxlab.eu/?p=731#comment-13100</guid>
		<description>i have received an e-mail this morning from dhl regarding this...tried to open it but it wouldnt let me...hope ive not done aything to my computer. the emial address they used for me wasnt mine but it managed to reach my computer. dont know how to get rid of this. anyone help please</description>
		<content:encoded><![CDATA[<p>i have received an e-mail this morning from dhl regarding this&#8230;tried to open it but it wouldnt let me&#8230;hope ive not done aything to my computer. the emial address they used for me wasnt mine but it managed to reach my computer. dont know how to get rid of this. anyone help please</p>
]]></content:encoded>
	</item>
</channel>
</rss>
