10/30/2012 5:44:06 AM POP3 filter email message from: FedEx <info@emails.fedex.com> to: query@[edited] with subject UPS: Your Package H2620555202 dated Tue, 30 Oct 2012 03:53:31 +0600 Win32/Cridex.AA worm contained infected files NOMENCLATURE\User1 Threat was detected upon receiving email by the application: C:\Program Files\Outlook Express\msimn.exe.
10/22/2012 7:30:54 PM POP3 filter email message from: "BBB Complaint Department" <info@la.bbb.org> to: <support@[edited]> with subject RE: Case #81229920 dated Mon, 22 Oct 2012 20:58:41 +0200 a variant of Win32/Kryptik.ANNG trojan contained infected files NOMENCLATURE\User1 Threat was detected upon receiving email by the application: C:\Program Files\Outlook Express\msimn.exe.
10/22/2012 8:48:41 AM POP3 filter email message from: "UPS Support" <Ranger.Leeywyea@charlina.gr> to: <query@[edited]> with subject UPS Invoice:16368154581 dated Mon, 22 Oct 2012 17:52:44 +0600 Win32/LockScreen.ANX trojan contained infected files NOMENCLATURE\User1 Threat was detected upon receiving email by the application: C:\Program Files\Outlook Express\msimn.exe.
10/22/2012 8:48:31 AM POP3 filter email message from: "UPS Support" <Coralie.Hillcaqfi@telesp.net.br> to: <qexmange@[edited]>, <query@[edited]>, <support@[edited]>, <nima@[edited]>, <sales@[edited]>, <gnilerg1986@[edited]> with subject UPS information #45009981553 dated Mon, 22 Oct 2012 02:04:39 -0500 Win32/LockScreen.ANX trojan contained infected files NOMENCLATURE\User1 Threat was detected upon receiving email by the application: C:\Program Files\Outlook Express\msimn.exe.
10/22/2012 8:37:40 AM POP3 filter email message from: "UPS Support" <Ranger.Leeywyea@charlina.gr> to: <query@[edited]> with subject UPS Invoice:16368154581 dated Mon, 22 Oct 2012 17:52:44 +0600 Win32/LockScreen.ANX trojan contained infected files NOMENCLATURE\User1 Threat was detected upon receiving email by the application: C:\Program Files\Outlook Express\msimn.exe.
10/22/2012 8:37:27 AM POP3 filter email message from: "UPS Support" <Coralie.Hillcaqfi@telesp.net.br> to: <qexmange@[edited]>, <query@[edited]>, <support@[edited]>, <nima@[edited]>, <sales@[edited]>, <gnilerg1986@[edited]> with subject UPS information #45009981553 dated Mon, 22 Oct 2012 02:04:39 -0500 Win32/LockScreen.ANX trojan contained infected files NOMENCLATURE\User1 Threat was detected upon receiving email by the application: C:\Program Files\Outlook Express\msimn.exe.
8/24/2012 6:28:45 AM POP3 filter email message from: LinkedIn Password <password@linkedin.com> to: support <support@[edited]> with subject United Postal Service Tracking Number H4476462328 dated Mon, 20 Aug 2012 03:02:38 -0800 Win32/Kryptik.AKOR trojan contained infected files NOMENCLATURE\User1 Threat was detected upon receiving email by the application: C:\Program Files\Outlook Express\msimn.exe.
8/21/2012 9:19:35 AM POP3 filter email message from: From: "notification@fedex.com" <notification@fedex.com> with subject FedEx Tracking Notification #822608005088 - Tue, 7 dated Tue, 7 Aug 2012 10:51:15 -0500 a variant of Win32/Kryptik.AJPK trojan contained infected files NOMENCLATURE\User1 Threat was detected upon receiving email by the application: C:\Program Files\Outlook Express\msimn.exe.
7/31/2012 5:47:54 PM POP3 filter email message from: "UPS TEAM 04" <manager_00@ups.com> to: <support@[edited]> with subject UPS: Your Package H9687608522 dated Mon, 30 Jul 2012 07:02:00 -0800 Win32/AutoRun.Spy.Banker.R worm contained infected files NOMENCLATURE\User1 Threat was detected upon receiving email by the application: C:\Program Files\Outlook Express\msimn.exe.
7/22/2012 10:40:29 AM POP3 filter email message from: FedEx <info@emails.fedex.com> to: query@[edited] with subject We can not diliver your package dated Fri, 20 Jul 2012 10:12:51 -0600 Win32/AutoRun.Spy.Banker.R worm contained infected files NOMENCLATURE\User1 Threat was detected upon receiving email by the application: C:\Program Files\Outlook Express\msimn.exe.
7/22/2012 10:35:28 AM POP3 filter email message from: FedEx <info@emails.fedex.com> to: support@[edited] with subject We can not diliver your package dated Fri, 20 Jul 2012 12:21:46 +0100 Win32/AutoRun.Spy.Banker.R worm contained infected files NOMENCLATURE\User1 Threat was detected upon receiving email by the application: C:\Program Files\Outlook Express\msimn.exe.