Articles Archive for May 2009

Other:W32/False Positive
Posted in F-Secure on 27 May 2009

When a legitimate file is detected as infected by an antivirus product, it is called a “false positive” or a “false alarm”.

Fast Antivirus 2009 System Alert
Posted in Information and Removal on 26 May 2009

If you ever come across this “system alert”:
System alert
Suspicious software, which may be malicious, has been detected on your PC. Click here to remove this threat immediately with Fast Antivirus 2009.
This so called “system alert” is a fake. As a matter of fact, it’s more than a fake - it is actually one of the [...]

Presto TuneUp System Alert
Posted in Information and Removal on 26 May 2009

If you see the following “system alert”:
System alert
Needless programs and files have been detected on your PC.
Click here to remove them immediately with Presto TuneUp.
Do not assume that it is a legitimate system alert. In reality this alert is displayed by the rogue  Presto TuneUp - a malicious programs which uses this and other means [...]

From IM to Twitter: Weight-Loss Spam Gains Ground
Posted in Information and Removal on 26 May 2009

A spam attack that has affected instant messaging users has found its way through Twitter, infiltrating users accounts to post messages with links connecting to weight-loss drugs.
Hacked Twitter accounts are being used to post messages that promote weight-loss drugs. The messages vary in the stated text, but generally states the same message and are [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

From IM to Twitter: Weight-Loss Spam Gains Ground

Citi Prepaid Phishing Services
Posted in Information and Removal on 26 May 2009

Formerly known as Ecount, Citi Prepaid Services is a prepaid solution for companies who aim for a customizable solution for payroll, sales incentives, benefit payments, etc. Recently we have encountered a phishing email, informing Citi Prepaid Services customers/clients that their account information needs to be updated due to inactive membership, purported causing fraud and report [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Citi Prepaid Phishing Services

WORM_NEERIS.L
Posted in Trend Micro on 26 May 2009

Malware: WORM_NEERIS.L

Worm:W32/Mabezat.B
Posted in F-Secure on 26 May 2009

A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network.

Brazil: Orkut Phishing Mail Leads to Data-Stealing Malware
Posted in Information and Removal on 25 May 2009

We recently captured a spam email that appeared to be from Orkut. It is written in Portuguese, and translates to the following (via GoogleTranslate):
Problems with your account.
Dear User,
We received some complaints against your profile saying you are “using copyrighted material,” and before Orkut disables your account unfairly, asks for you to contact us stating the [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Brazil: Orkut Phishing Mail Leads to Data-Stealing Malware

“Testversion” popup
Posted in Information and Removal on 25 May 2009

The following popup:
“Testversion. ACHTUNG. Unser Scanner hat zahlreiche Probleme auf lhrem PC gefunden, die sofort nach dem Kauf eines zum Freischalten unseres Programms notwendigen Aktivierungscodes gelost werden konnen. Um den Aktivierungscode zu erwerben, klicken Sie HIER.”
is not a legitimate warning, but rather a misleading popup displayed by the rogue anti-virus program Antivirus Doktor. This parasite [...]

Advanced Virus Remover System Warning
Posted in Information and Removal on 25 May 2009

If you encounter the following tray popup:
System warning!
Intercepting programs that may compromise your privacy and harm your system have been detected on your PC. It’s highly recommended you scan your PC right now.
Do not assume it’s a genuine alert: it is merely a means to scare you, used by the fake anti-virus program Advanced Virus [...]