<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27; in Security</title>
<link>http://www.dslreports.com/forum/r18160282</link>
<description></description>
<language>en</language>
<pubDate>Tue, 09 Feb 2010 22:39:06 EDT</pubDate>
<lastBuildDate>Tue, 09 Feb 2010 22:39:06 EDT</lastBuildDate>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18178143</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : Has anyone tried this bad boy in with a virtual system as we might have a no goer in a virtual environment.<br><br>Blake]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18178143</guid>
<pubDate>Mon, 16 Apr 2007 00:14:19 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18172871</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  59126125 <A HREF="/useremail/u/1317191"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Sure the idea is on the paranoid side, but if someone wanted to harvest as much personal info as possible in the shortest amount of time, wouldn't tax time be the prime opportunity? What if someone created a root kit or whatever that targeted tax prep programs like TurboTax, etc.?<br> </DIV>That was exactly the point that I was trying to get at. Who's to say that you couldn't use a software program like TurboTax and have a key logger installed on the same computer.<br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18172871</guid>
<pubDate>Sat, 14 Apr 2007 22:53:55 EDT</pubDate>
</item>

<item>
<title>Re: Forecast - Massive Storms clouded by Rootkits</title>
<link>http://www.dslreports.com/forum/remark,18172660</link>
<description><![CDATA[<A HREF="/useremail/u/1193253"><b>SpannerITWks</b></A> : That link goes to - hxxp://64.28.178.4/index.php - and is associated with -<br><br>hxxp://free-orgy-movies.com<br><br>( This domain name parked on Estparking.com. To buy this domain click here. )<br><br>I was on an exact replica of that www - hxxp://moviefresher.com - in the last 1/2 hour, as i found it linked to a Zlob www i was DL'ing from.<br><br>Spanner<br><SMALL>--<br>I Only Know What I Know, But I'm Learning all The Time - Stay Safe - Spanner intheWorks<br>/SpannerITWks</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18172660</guid>
<pubDate>Sat, 14 Apr 2007 22:16:58 EDT</pubDate>
</item>

<item>
<title>Forecast - Massive Storms clouded by Rootkits</title>
<link>http://www.dslreports.com/forum/remark,18172593</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : The above subject title from<br><br>&raquo;<A HREF="http://www.antirootkit.com/blog/" >www.antirootkit.com/blog/</A><br>"The Rootkit component is wincom32.sys"<br><BR><br>I permitted the patch file to extract, then re-enabled security to watch it run:<br><BR><br> <IMG SRC="http://www.urs2.net/rsj/computing/imgs/patch_wincom32sys.gif"> <br>________________________________________________________________<BR><br>The loading of the rootkit component, driver wincom32.sys (an executable) is blocked. Then I permitted wincom32.sys to install, and it immediately attempted an outbound connection: <br><br><BR><br> <IMG SRC="http://www.urs2.net/rsj/computing/imgs/patch_kerio.gif"> <br>_________________________________________________________<br><br>A search doesn't reveal the wincom32.sys file.<br><br> <IMG SRC="http://www.urs2.net/rsj/computing/imgs/patch_files.gif"> <br>_________________________________________________________<br><BR><br>Also, none of the Registry entries mentioned in the analysis show up.<br><br>A final quote from the analysis:<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>The latest Storm run was seen on the radar about 6 PM GMT on Thursday and within 24 hours over 55 million emails were sent out by the Worm according to Postini, an email security company. This is over 60 times the normal rate for a &#147;normal&#148; 24 hour period.<br><br>The fact that this Storm run is so massive just goes to show that PC users all over the world are opening up encrypted zipped attachments from strangers and running the code.<HR></BLOCKQUOTE><BR><br>regards,<br><br>-rich<BR><br>______________________________________________<br><SMALL>"Talking About Security Can Lead To Anxiety, Panic, And Dread... <br>Or Cool Assessments, Common Sense And Practical Planning..."<br>  <BLOCKQUOTE>   --Bruce Schneier</SMALL></BLOCKQUOTE>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18172593</guid>
<pubDate>Sat, 14 Apr 2007 22:05:15 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18172338</link>
<description><![CDATA[<A HREF="/useremail/u/1317191"><b>59126125</b></A> : Sure the idea is on the paranoid side, but if someone wanted to harvest as much personal info as possible in the shortest amount of time, wouldn't tax time be the prime opportunity? What if someone created a root kit or whatever that targeted tax prep programs like TurboTax, etc.?<br><SMALL>--<br>There is a reason the wires are twisted together, it's called a pair. It defeats the whole purpose of twisted pair cabling by using the solid orange and solid green to wire the jack.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18172338</guid>
<pubDate>Sat, 14 Apr 2007 21:11:24 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18171702</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  59126125 <A HREF="/useremail/u/1317191"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Isn't it a little strange that this is occurring close to the deadline for filing taxes? Or is it just coincidence? &raquo;<A HREF="http://news.yahoo.com/s/ap/20070414/ap_on_bi_ge/taxes_ap_poll;_ylt=ApzzNnqTbhr8rfxAKg9pJAJvzwcF" >news.yahoo.com/s/ap/20070414/ap_&middot;&middot;&middot;JAJvzwcF</A><br> </DIV>Are you referring that internet users will use infected computers, not knowing that their tax information will  end up in the hands of cybercriminals through the use of a root kit or key logger<br><br>Interesting theory.  :D<br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18171702</guid>
<pubDate>Sat, 14 Apr 2007 19:03:41 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18171023</link>
<description><![CDATA[<A HREF="/useremail/u/1317191"><b>59126125</b></A> : Isn't it a little strange that this is occurring close to the deadline for filing taxes? Or is it just coincidence? &raquo;<A HREF="http://news.yahoo.com/s/ap/20070414/ap_on_bi_ge/taxes_ap_poll;_ylt=ApzzNnqTbhr8rfxAKg9pJAJvzwcF" >news.yahoo.com/s/ap/20070414/ap_&middot;&middot;&middot;JAJvzwcF</A><br><SMALL>--<br>There is a reason the wires are twisted together, it's called a pair. It defeats the whole purpose of twisted pair cabling by using the solid orange and solid green to wire the jack.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18171023</guid>
<pubDate>Sat, 14 Apr 2007 16:42:14 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18170405</link>
<description><![CDATA[<A HREF="/useremail/u/445404"><b>Martinus</b></A> : <div class="bquote"><SMALL>said by  quatrix <A HREF="/useremail/u/1157186"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  Martinus <A HREF="/useremail/u/445404"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</SMALL><br><br>Probably a good idea not to ditch your AV just because you are an eagle to spot grammatical flaws right away.</DIV>Eagle?  If you read the message, even the first sentence sounds obviously wrong.<br> </DIV>Yeah, to you. But probably not to everybody.<br><br>I've seen more atrocities committed against the English language in this forum than I though was possible.<br><br>People writing "their" when they mean "there", "here, here Microsoft" when they, obviously meant "hear, hear Microsoft", and so on. So yes, a grammar check will quickly give a clue to some but don't expect that'll help everybody.<br><SMALL>--<br>Si naciste pa' martillo del cielo te caen los clavos</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18170405</guid>
<pubDate>Sat, 14 Apr 2007 14:09:15 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18169753</link>
<description><![CDATA[<A HREF="/useremail/u/1157186"><b>quatrix</b></A> : <div class="bquote"><SMALL>said by  Martinus <A HREF="/useremail/u/445404"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Probably a good idea not to ditch your AV just because you are an eagle to spot grammatical flaws right away.</DIV>Eagle?  If you read the message, even the first sentence sounds obviously wrong.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18169753</guid>
<pubDate>Sat, 14 Apr 2007 11:49:46 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18169518</link>
<description><![CDATA[<A HREF="/useremail/u/737475"><b>BosstonesOwn</b></A> : Yeah for us. What about the normal people.<br><br>My email box is full of these because we support windows servers now too. And most of the windows shops are getting hammered with this.<br><SMALL>--<br> "It's always funny until someone gets hurt......and then it's absolutely friggin' hysterical!"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18169518</guid>
<pubDate>Sat, 14 Apr 2007 10:40:53 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18169212</link>
<description><![CDATA[<A HREF="/useremail/u/195272"><b>Rickez</b></A> : Times like this I thank god for common sense.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18169212</guid>
<pubDate>Sat, 14 Apr 2007 09:00:18 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18168634</link>
<description><![CDATA[<A HREF="/useremail/u/1140294"><b>Blackbird</b></A> : <div class="bquote"><SMALL>said by  Martinus <A HREF="/useremail/u/445404"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>English is not my native language but I've seen sentences in these forums - heck. nearly in most forums - by native English speakers with more grammatical or syntactical flaws than the ones you mention.<br><br>I don't think grammar can be used as a malware giveaway in this context. For the illustrated, probably. For the rest, I doubt it. </DIV> Perhaps I didn't express myself well. I was referring to the fact that phishes, fake patches, and the like all purport to be from established, reputable organizations. But my experience has been that "official" notification messages sent out by legitimate groups have almost always been vetted for basic spelling or grammar... either by spell/grammar checkers or by an educated author. That doesn't mean an error might not pop up in a legitimate message, but it does mean that a collection of obvious errors in a message almost certainly guarantees it's not any kind of official notice being broadcast by a legitimate organization. As a result, whenever I encounter an error-filled, purportedly "official" message, I generally look no further and simply hit the delete button. <br><br>Obviously, those with less English-language experience will not be able to do that... but that's why nobody should be opening executables or naively trusting URL links contained in any unsolicited eMail, regardless of language or where they live. And in any case, if the language looks OK, I still practice safe-hex in not opening attachments or assuming links are valid without first cross-checking 100% with the real purported sender by direct, person-to-person or other secure, independent means. <br><br>Verify, verify, verify.<br><SMALL>--<br>If God wanted us to work with electrons, He'd make them big enough to see...</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18168634</guid>
<pubDate>Sat, 14 Apr 2007 01:54:40 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18167634</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  pcdebb <A HREF="/useremail/u/254898"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>::sigh:: i already got two people that already installed the "update" and wondered what it was AFTERWARDS  :mad:<br> </DIV>Once again  :(,the combination of naive internet plus social engineering, does equal the slow destruction of the internet.<br><br>We all pay for it , in the end.  You have to look at the big picture of the whole thing.  It's such a sad state when you can allow someone to use the internet, and they don't have<br>a clue on what is involved with internet security. :( :(<br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18167634</guid>
<pubDate>Fri, 13 Apr 2007 21:38:17 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18167595</link>
<description><![CDATA[<A HREF="/useremail/u/254898"><b>pcdebb</b></A> : ::sigh:: i already got two people that already installed the "update" and wondered what it was AFTERWARDS  :mad:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18167595</guid>
<pubDate>Fri, 13 Apr 2007 21:28:52 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18167094</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  BosstonesOwn <A HREF="/useremail/u/737475"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Times like these I thank god for Solaris 10 :)<br> </DIV>If I had a choice to move to another operating system, it would be Linux Fedora Red Hat 7.   :D :D :D :D :D :D<br><br>I mean it's not that I don't like Microsoft Vista  :),  but the new security exploits are are starting to get a little old now.<br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18167094</guid>
<pubDate>Fri, 13 Apr 2007 19:50:17 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18165655</link>
<description><![CDATA[<A HREF="/useremail/u/737475"><b>BosstonesOwn</b></A> : Times like these I thank god for Solaris 10 :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165655</guid>
<pubDate>Fri, 13 Apr 2007 15:37:23 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18165352</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  Jameson <A HREF="/useremail/u/1014733"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Yup:<br>User-Agent:<br>Thunderbird 1.5.0.9 (Windows/20061207)<br><br>EDIT:<br>However it was From:<br>Customer Support <br> </DIV>One of the patterns that I have been noticing is that Yahoo email accounts are one of the targets. Every email contains the header line  <B>"Thunderbird 1.5.0.9 (Windows/20061207)"</B>  being sent through zombie machines in Europe and the United States.<br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165352</guid>
<pubDate>Fri, 13 Apr 2007 14:40:47 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18165349</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : The "Thunderbird" user-agent header seems to be consistent across this entire spam run.  It's probably hard-coded.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165349</guid>
<pubDate>Fri, 13 Apr 2007 14:40:39 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18165307</link>
<description><![CDATA[<A HREF="/useremail/u/1014733"><b>Jameson</b></A> : Yup:<br>User-Agent:<br>Thunderbird 1.5.0.9 (Windows/20061207)<br><br>EDIT:<br>However it was From:<br>ohhsj @ icqmail.com<br><br>X-Originating-IP:<br>[216.141.228.112]<br>Authentication-Results:<br>mta121.sbc.mail.mud.yahoo.com from=icqmail.com; domainkeys=neutral (no sig)<br>Received:<br>from 207.115.36.76 (EHLO nlpi047.sbcis.sbc.com) (207.115.36.76) by mta121.sbc.mail.mud.yahoo.com with SMTP; Thu, 12 Apr 2007 23:07:56 -0700<br>X-Header-NoReverseIP:<br>IP.name.lookup.failed[216.141.228.112]<br>X-Originating-IP:<br>[216.141.228.112]]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165307</guid>
<pubDate>Fri, 13 Apr 2007 14:32:17 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18165276</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  Jameson <A HREF="/useremail/u/1014733"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Got one as well this morning.<br><br>The one i got was called removal-8736.zip<br> </DIV>Did the email header contain the information "User-Agent: Thunderbird 1.5.0.9 (Windows/20061207)"  and was it from a Yahoo email account?<br><br>X-Apparently-To: html_edit@yahoo.com via 68.142.198.159; Thu, 12 Apr 2007 11:27:33 -0700 <br>X-YahooFilteredBulk: 162.39.116.180 <br><B>X-Originating-IP: [162.39.116.180]</B> <br>Return-Path:  <br>Authentication-Results: mta434.mail.mud.yahoo.com from=med.va.gov; domainkeys=neutral (no sig) <br>Received: from 162.39.116.180 (HELO h180.116.39.162.ip.alltel.net) (162.39.116.180) by mta434.mail.mud.yahoo.com with SMTP; Thu, 12 Apr 2007 11:27:32 -0700 <br>Received: from vqyhx ([26.84.210.33]) by h180.116.39.162.ip.alltel.net (8.13.4/8.13.4) with SMTP id l3CIm64j074509; Thu, 12 Apr 2007 14:48:06 -0400 <br>Message-ID:  <br>Date: Thu, 12 Apr 2007 14:44:50 -0400 <br><B>From: "Customer Support Center" </B>  <br><B>User-Agent: Thunderbird 1.5.0.9 (Windows/20061207) </B><br>MIME-Version: 1.0 <br>To: html_edit@yahoo.com <br><B>Subject: Virus Detected! </B><br>Content-Type: multipart/mixed; boundary="------------040808030703010202050005" <br>Content-Length: 60246 <br><br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165276</guid>
<pubDate>Fri, 13 Apr 2007 14:25:31 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18165186</link>
<description><![CDATA[<A HREF="/useremail/u/472725"><b>luddite</b></A> : <div class="bquote"><SMALL>said by  Martinus <A HREF="/useremail/u/445404"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR><div class="bquote"><SMALL>said by  Blackbird <A HREF="/useremail/u/1140294"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br> Purely from the code perspective, yes. But these guys <B>still</B> can't get seem to get their spelling/grammar right: "adress", "becouse", "We recommend you to install...", "We had archived the patch...".<br> </DIV>English is not my native language but I've seen sentences in these forums - heck. nearly in most forums - by native English speakers with more grammatical or syntactical flaws than the ones you mention.<br><br>I don't think grammar can be used as a malware giveaway in this context. For the illustrated, probably. For the rest, I doubt it.<br> </DIV>On the flip side I think that bad spelling/grammar is only a tip-off to those who are pretty fluent and proficient with the English language to begin with (which is probably a very small percent of the total users on the internet).<br><br>My in-laws don't speak English as their primary language and I would be willing to bet that they would be easily fooled by the supposed 'officialness' of such an email as this.  I've had to reformat one PC in their household on two separate occasions so far... No idea how it got infected exactly (I suspect pr0n sites) but I wouldn't be surprised to find out they fell for some such email attack such as this.<br><br>I guess what I'm trying to say is that there are many, many, many people out there on the internet for which English is not their primary language and this email will not be viewed as an obvious 'scam' simply due to poor grammar.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165186</guid>
<pubDate>Fri, 13 Apr 2007 14:08:25 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18165147</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : That's been one busy robot.  :D<br><br>These "Storm Worm" variants are one of the few items that seem to be able to regularly "punch-through" my greylister.  Good thing that it hits F-prot when it reaches my  mail server and then NOD32 when it gets downloaded to the desktop.<br><SMALL>--<br>Windows Vista has detected that your mouse was moved. In order to enhance your user experience, Vista needs to contact Microsoft to re-activate the software. Please make sure you are connected to the Internet, have your credit card handy, then click OK.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165147</guid>
<pubDate>Fri, 13 Apr 2007 13:58:35 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18165115</link>
<description><![CDATA[<A HREF="/useremail/u/1014733"><b>Jameson</b></A> : Got one as well this morning.<br><br>The one i got was called removal-8736.zip<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18165115?c=1151404&ret=L2ZvcnVtL3IxODE2MDI4Mi54bWw%3D"><IMG TITLE="4759 bytes" BORDER=0 WIDTH=520 HEIGHT=281 SRC="/r0/download/1151404~5bd2dbc175702584dabad267dbac95fd/Complaint.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165115</guid>
<pubDate>Fri, 13 Apr 2007 13:50:49 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18165071</link>
<description><![CDATA[<A HREF="/useremail/u/445404"><b>Martinus</b></A> : <div class="bquote"><SMALL>said by  kpatz <A HREF="/useremail/u/825971"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  Martinus <A HREF="/useremail/u/445404"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>I don't think grammar can be used as a malware giveaway in this context. For the illustrated, probably. For the rest, I doubt it. </DIV>So far, every piece of malware I've received in email has had lousy spelling or grammar in the message, if there is a message at all.<br><br>So, if you receive an email that is well written, spelled correctly, no typos, and no grammatical errors, chances are it wasn't created by a spammer or a virus/worm. :)<br> </DIV>Yes. If it's well written, it probably comes from MS PR monkeys :)<br><br>But, hey, malware writers will probably get it grammatically right at some point by trial and error.<br><br>Probably a good idea not to ditch your AV just because you are an eagle to spot grammatical flaws right away.<br><SMALL>--<br>Si naciste pa' martillo del cielo te caen los clavos</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165071</guid>
<pubDate>Fri, 13 Apr 2007 13:41:26 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18165030</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : <div class="bquote"><SMALL>said by  Martinus <A HREF="/useremail/u/445404"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>I don't think grammar can be used as a malware giveaway in this context. For the illustrated, probably. For the rest, I doubt it. </DIV>So far, every piece of malware I've received in email has had lousy spelling or grammar in the message, if there is a message at all.<br><br>So, if you receive an email that is well written, spelled correctly, no typos, and no grammatical errors, chances are it wasn't created by a spammer or a virus/worm. :)<br><SMALL>--<br>Windows Vista has detected that your mouse was moved. In order to enhance your user experience, Vista needs to contact Microsoft to re-activate the software. Please make sure you are connected to the Internet, have your credit card handy, then click OK.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165030</guid>
<pubDate>Fri, 13 Apr 2007 13:32:31 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18165015</link>
<description><![CDATA[<A HREF="/useremail/u/445404"><b>Martinus</b></A> : <div class="bquote"><SMALL>said by  Blackbird <A HREF="/useremail/u/1140294"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br> Purely from the code perspective, yes. But these guys <B>still</B> can't get seem to get their spelling/grammar right: "adress", "becouse", "We recommend you to install...", "We had archived the patch...".<br> </DIV>English is not my native language but I've seen sentences in these forums - heck. nearly in most forums - by native English speakers with more grammatical or syntactical flaws than the ones you mention.<br><br>I don't think grammar can be used as a malware giveaway in this context. For the illustrated, probably. For the rest, I doubt it.<br><SMALL>--<br>Si naciste pa' martillo del cielo te caen los clavos</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165015</guid>
<pubDate>Fri, 13 Apr 2007 13:29:42 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18164892</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : <div class="bquote"><SMALL>said by  Blackbird <A HREF="/useremail/u/1140294"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>If the creative coders ever hooked up with good writers, these things probably wouldn't be as easy to spot simply on the basis of the goofy message texts.<br> </DIV>True, but those folks do hook up for different "campaigns."  <br><br>These e-mails are more than sufficiently effective on the users they are targeting, idiosyncrasies and all.  The Storm Worm group did very well using pure EXE attachments in January; just about anyone that fell for that is likely to fall for this, too.<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18164892</guid>
<pubDate>Fri, 13 Apr 2007 13:07:22 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18164449</link>
<description><![CDATA[<A HREF="/useremail/u/1404903"><b>DrModem</b></A> : I got that the other day, recognized it as a virus and took care of it. It's too corny to fool me lol.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18164449</guid>
<pubDate>Fri, 13 Apr 2007 11:30:40 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18164266</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : <div class="bquote"><SMALL>said by  antiphishing <A HREF="/useremail/u/1021645"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>My thoughts exactly.<br></DIV>If that ever happens, it will be the end of the Internet, since no one who receives an email with correct spelling and grammar is going to think it contains a virus.  :D<br><SMALL>--<br>Windows Vista has detected that your mouse was moved. In order to enhance your user experience, Vista needs to contact Microsoft to re-activate the software. Please make sure you are connected to the Internet, have your credit card handy, then click OK.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18164266</guid>
<pubDate>Fri, 13 Apr 2007 10:50:26 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18164257</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  Blackbird <A HREF="/useremail/u/1140294"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><SMALL>said by  Link Logger <A HREF="/useremail/u/356416"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>If the creative coders ever hooked up with good writers, these things probably wouldn't be as easy to spot simply on the basis of the goofy message texts.<br> </DIV>My thoughts exactly. :D <br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18164257</guid>
<pubDate>Fri, 13 Apr 2007 10:48:04 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18163053</link>
<description><![CDATA[<A HREF="/useremail/u/1140294"><b>Blackbird</b></A> : <div class="bquote"><SMALL>said by  Link Logger <A HREF="/useremail/u/356416"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>... This is an attack with a higher level of sophistication then the usual slash and dump as someone did some coding on this. </DIV> Purely from the code perspective, yes. But these guys <B>still</B> can't get seem to get their spelling/grammar right: "adress", "becouse", "We recommend you to install...", "We had archived the patch...".<br><br>If the creative coders ever hooked up with good writers, these things probably wouldn't be as easy to spot simply on the basis of the goofy message texts.<br><SMALL>--<br>If God wanted us to work with electrons, He'd make them big enough to see...</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18163053</guid>
<pubDate>Fri, 13 Apr 2007 01:36:37 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18162540</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : NOD32 picked it up when you try to unpack it as the zip file is password protected so no AV is going to detect it in that state, its when it unpacks that is when your AV should pick it up.<br><br>We are going to see a lot of these as it using the typical randomly generated user ids married up with the domain name, ditto for the reply so if you bounce it, some other unsuspecting Joe might get it as a bounced email.  The usual distribution method.<br><br>It actually an interesting attack in that it takes the malware zips it up with password protection where the password is randomly generated and an accompanying gif is generated and packaged with the password.  Thus far the passwords all have the same pattern 3 letters followed by 2 digits.  This is an attack with a higher level of sophistication then the usual slash and dump as someone did some coding on this.<br><br>Blake<br><SMALL>--<br>Vendor: Author of <A HREF="http://www.linklogger.com">Link Logger</A> which is a traffic analysis and firewall logging tool</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18162540</guid>
<pubDate>Thu, 12 Apr 2007 23:20:05 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18162370</link>
<description><![CDATA[<A HREF="/useremail/u/1003137"><b>garys_2k</b></A> : I just submitted the zip file to virustotal and pitifully few scanners picked it up. My Avira Antivir passed it right by - maybe the encryption fooled it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18162370</guid>
<pubDate>Thu, 12 Apr 2007 22:46:26 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18162097</link>
<description><![CDATA[<A HREF="/useremail/u/1226902"><b>rotty97</b></A> : LOL, the .exe "patch" has to unpack at sometime to run..............]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18162097</guid>
<pubDate>Thu, 12 Apr 2007 21:56:32 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18161351</link>
<description><![CDATA[<A HREF="/useremail/u/262428"><b>rds24a</b></A> : Several different builds of KIS 6 seem to have no problems deleting it. I've seen around 10 of them at three different locations....all on rr.com<br><SMALL>--<br>All hail JoePa</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18161351</guid>
<pubDate>Thu, 12 Apr 2007 19:44:01 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18161332</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  kpatz <A HREF="/useremail/u/825971"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Just got another one, in my Yahoo account this time.<br><br>Attached file is Patch_2119.zip.<br> </DIV>A massive spam outbreak that tries to trick recipients into opening a file attachment that can hijack their computers has already broken records, security companies said today. Researchers at Postini Inc. said the spam run is the largest in the last 12 months....<br>&raquo;<A HREF="http://cwflyris.computerworld.com/t/1445594/6163408/59068/2/" >cwflyris.computerworld.com/t/144&middot;&middot;&middot;59068/2/</A><br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/speak/slideshow/18161332?c=1151129&ret=L2ZvcnVtL3IxODE2MDI4Mi54bWw%3D"><IMG TITLE="172 bytes" BORDER=0 WIDTH=16 HEIGHT=15 SRC="/r0/download/1151129~7986022c0435833a708c5aa160f0da96/imsgm.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18161332</guid>
<pubDate>Thu, 12 Apr 2007 19:40:24 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18161183</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  boognish <A HREF="/useremail/u/483140"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Our exchange server is getting pounded by this one today.  I normally see maybe 50 virus warnings from the exchange server a day.   Today it has been well over 2000.   I have been blocking certain IPs but haven't had a chance to go put some rules in spamassassin to block which I need to do.<br> </DIV>Subject  Support Team   Virus Activity Detected! 60k<br>Subject  Customer Support Center Virus Detected! 60k<br>Subject  Arthur   A Is For Attitude              70k<br>Subject  welfare   Our Love Nest                 70k<br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18161183</guid>
<pubDate>Thu, 12 Apr 2007 19:09:57 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18160411</link>
<description><![CDATA[<A HREF="/useremail/u/483140"><b>boognish</b></A> : Our exchange server is getting pounded by this one today.  I normally see maybe 50 virus warnings from the exchange server a day.   Today it has been well over 2000.   I have been blocking certain IPs but haven't had a chance to go put some rules in spamassassin to block which I need to do.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18160411</guid>
<pubDate>Thu, 12 Apr 2007 16:37:53 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18160282</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Just got another one, in my Yahoo account this time.<br><br>Attached file is Patch_2119.zip.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18160282?c=1151060&ret=L2ZvcnVtL3IxODE2MDI4Mi54bWw%3D"><IMG TITLE="4775 bytes" BORDER=0 WIDTH=503 HEIGHT=290 SRC="/r0/download/1151060~5bd2dbc175702584dabad267dbac95fd/Complaint.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18160282</guid>
<pubDate>Thu, 12 Apr 2007 16:16:06 EDT</pubDate>
</item>

<item>
<title>Re: Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18160260</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Not just Yahoo accounts, I'm seeing them on my personal email too.<br><br>It's the latest variant of the Mixor/Nuwar/"Storm Worm" outbreak that's been hitting this week (name varies widely by AV vendor).<br><br>Whatever is sending them (worm or spambot) is pretty adept at punching through my greylister too.  Fortunately I have multiple layers of virus scanning on my personal email as well. :)<br><br>Up until now they've all been just straight .exe attachments, but this latest one has taken the Bagle approach of sending itself as a password-protected zip attachment.  The upside is my email anti-virus setup strips encrypted zips, so no definition updates are needed.<br><SMALL>--<br>Windows Vista has detected that your mouse was moved. In order to enhance your user experience, Vista needs to contact Microsoft to re-activate the software. Please make sure you are connected to the Internet, have your credit card handy, then click OK.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18160260</guid>
<pubDate>Thu, 12 Apr 2007 16:11:53 EDT</pubDate>
</item>

<item>
<title>Warning regarding  fake malware patch  &#x27;patch_4723.zip &#x27;</title>
<link>http://www.dslreports.com/forum/remark,18160227</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : The file 'patch_4723.zip' is being sent to yahoo accounts telling internet users to install the attactment as a patch. <br><br>Date: Thu, 12 Apr 2007 20:38:44 +0200 <br>From: "Postmaster"    <br>Thunderbird 1.5.0.9 (Windows/20061207) <br>MIME-Version: 1.0 <br>To: sgtpepper_1967@yahoo.com <br>Subject: ATTN! <br><br>File name: patch_4723.zip <br>File size: 38kb <br>File type: application/octet-stream <br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18160227?c=1151053&ret=L2ZvcnVtL3IxODE2MDI4Mi54bWw%3D"><IMG TITLE="4705 bytes" BORDER=0 WIDTH=475 HEIGHT=286 SRC="/r0/download/1151053~3cb674bbd9a940f6fd7b1bc2696f3b4e/AbuseNotice.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18160227</guid>
<pubDate>Thu, 12 Apr 2007 16:06:44 EDT</pubDate>
</item>

</channel>
</rss>
