Sorry... There is one little mistake in the posted rule... Changed the ...[1-9]... to ...[0-9]... It's late ;-) The changed rule: rawbody BagleQ_Found /(?:\<object\s{1,3}style\=\Sdisplay\:none.{1,5} data\=.http\:\/\/([0-9]+[\.|\:|\/])+\w+\.php)/i describe BagleQ_Found Worm Bagle-Q found score BagleQ_Found 10.0 Holger