Hi all, Looks like we just got a run of a fake ConXflicker.BXInfectionXAlert (remove X's) this time with an install zip payload. A variant of: http://blogs.zdnet.com/security/?p=3105 Just added Detection as: Sanesecurity.Malware.12892 Sanesecurity.Malware.12893 Sanesecurity.Malware.12894 Cheers, Steve Sanesecurity