SecGeeks Alert : Fake Conflicker/Downadup removal tool spreading through email

Hacker Halted 2010

599
vote

I have received this mail today:
"Dear windows User,

Following a recent outbreak of the conflicker worm also known as downadup or trojan/brisv.a affecting over 15million Microsoft Windows users.. Merely
visiting a lot of popular sites could have gotten you infected. The virus exploited a vulnerability in all windows versions and products including the windows xp and vista operating systems. Researchers at Microsoft have
been working closely with Symantec, the creators of Norton antivirus and have come up with a removal tool for the conflicker virus. The average anti-virus
software is not capable of detecting the conflicker worm as it changes each time on start-up. The virus also recently updated itself making it much harder to detect.
Please note that an update has already been released and will have been installed by windows update if you have a legal copy of windows. The update prevents
new access by the virus to your computer but it does not remove it if you were already infected prior to the release of the update.
You are hereby immediately advised to download and run the removal tool from the link provided below to make sure you are not infected and prevent loss of
your data and theft of personal and financial information. Please take your time to do this immediately.

Usage Instructions:
download file
click remtool_conf.exe and let it scan..
you are advised to disable your already existing antivirus software prior to running the removal tool to avoid conflicts.

click here to download the removal tool

Please note that Microsoft is working closely with the F.B.I to apprehend the creators of the virus and is even offering a 250,000 reward for any
information leading to their arrest. More details here

Thanks for your cooperation and for bearing with us
Microsoft Security Department

This email is not equipped to handle replies.

your potential our passion
© 2009 Microsoft Corporation. All rights reserved."

here it is clear that it i using conflicker aka downadup name to spread itself.it download a exe file and no antivirus is catching it at this moment.here are the virus total results:
http://www.virustotal.com/analisis/d6523a0e49f206812c3c9e9181b719477f446e92add4cf132e6f2b79b2982081-1244640740
this mail comes from "securitydept@microsoft.ssl.com" and its reply to address is: "securitydept@microsoft.ssl.com"
i have not analysed it but it looks suspicious for sure..please see the screen shots bellow :

Trackback URL for this post:

http://secgeeks.com/trackback/2803