Today I received a mail that had the subject "A new settings file for
the (notmyownlocalpart)@t-online.de has just been released", which
according to VT contained the downloader for a trojan horse.
How many of you got them, too? Avira calls it a ZBot variant and says
it will steal banking data, see
http://www.avira.com/en/threats/section/fulldetails/id_vir/4543/tr_spy.zbot.9164.1.html
Microsoft identifies it as FakeRean which is a fake/rogue "antivirus".
Weird.
Googling for the sequence of the first five words already provides a
considerable number of hits, and none of the linked entries seems to be
older than three weeks. Is this a new spamrun / attack of a certain
malware group?
Gabriele Neukam
--
Often those who most loudly proclaim their freedom to choose in some
fields are the most retentive about 'correcting' others' choices in
other fields.
(Brian Brunner in alt.games.diablo2)