Symptoms
The user receives a mail on yahoo with the subject line containing "shell" or "c99" (for example "wtf is c99shell" , "a shell written in php??" or "look what I found, shell") and the body containing for example: "check this c99 russian php shell script"
Another case is when mail seems to be from hi5.com with a legitimate subject like "some_name_here has sent you a hi5 Friend Request", where the user is prompted to click a link to accept his new friend, link which is not pointing to hi5.com.
Removal instructions:
Delete those mails described in "Symptoms" and change your password immediately!
Analyzed By
Sorin Ciorceri, virus researcher
SHARE
THIS ON