There is a newer spam/virus email circulating (seems to be mostly corporate domains) the tries to entice the recipient to click on an http: link that links to a viral zip file.
Here are examples:
From: domain.com support
Sent:
To: User
Subject: [SPAM (Non-existent user)] - setting for your mailbox user@domain.com are changed
SMTP and POP3 servers for user@domail.com mailbox are changed. Please carefully read the attached instructions before updating settings.
http://creterx.googlegroups.com/web/setup.zip
________________________
From: domain.com support [mailto:user@domain.com]
Sent:
To: User
Subject: setting for your mailbox user@domain.com are changed - Email contains a url listed on "multi.surbl.org"
SMTP and POP3 servers for user@domain.com mailbox are changed.
Please carefully read the attached instructions before updating settings.
"http://mamapapabrat.googlegroups.com/web/setup.zip"