Showy malware pushes rogue anti-malware product

Posted by   Virus Bulletin on   Mar 4, 2008

MonaRonaDona trojan leads searchers to remover scam.

An infection which advertises its presence using the name 'MonaRonaDona' is leading victims to search for a cure - and many of them are finding a targeted rogue anti-malware application widely promoted on the web as a dedicated fix for the problem.

In stark contrast to the stealth practised by most modern malware, the infection makes itself very clear to users of infected systems, shutting down a raft of core applications including most of Microsoft's Office suite and popping up a message boasting of the infection, claiming to carry a political message about human rights abuses.

With the self-applied name 'MonaRonaDona' clearly advertised, users searching for the string are likely to find sites pushing an apparent anti-malware product called Unigray. This operates in the standard manner of the genre, alerting on numerous spurious infections on clean systems, including false positive alerts on the 'MonaRonaDona' name, and requiring a payment for a fully functioning version supposedly capable of cleaning the 'infections'.

Readers are advised only to use security software with a solid reputation and a strong history in independent testing. Full details of the Unigray scam are in a Kaspersky Labs blog entry here.

Posted on 04 March 2008 by Virus Bulletin



Latest posts:

New paper: LokiBot: dissecting the C&C panel deployments

First advertised as an information stealer and keylogger when it appeared in underground forums in 2015, LokiBot has added various capabilities over the years and has affected many users worldwide. In a new paper researcher Aditya Sood analyses the…

VB2019 presentation: Building secure sharing systems that treat humans as features not bugs

In a presentation at VB2019 in London, Virtru's Andrea Limbago described how, by exploring data sharing challenges through a socio-technical lens, it is possible to make significant gains toward the secure sharing systems and processes that are vital…

VB2019 presentation: Attor: spy platform with curious GSM fingerprinting

Attor is a newly discovered cyber-espionage platform, use of which dates back to at least 2014 and which focuses on diplomatic missions and governmental institutions. Details of Attor were presented at VB2019 in London by ESET researcher Zuzana…

Why we encourage newcomers and seasoned presenters alike to submit a paper for VB2020

With the call for papers for VB2020 currently open, we explain why, whether you've never presented before or you're a conference circuit veteran, if you have some interesting research to share with the community we want to hear from you!

VB2019 paper: The cake is a lie! Uncovering the secret world of malware-like cheats in video games

At VB2019 in London, Kaspersky researcher Santiago Pontiroli presented a paper on the growing illegal economy around video game cheats and its parallels with the malware industry. Today we publish both Santiago's paper and the recording of his…

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.