Fake YouTube Messages – Your Account is Infected!

I was just doing my morning email chores when I stumbled across an email from my YouTube account.  This is what it said:

s0m3b0de has sent you a message:

Your Account is Infected
Your YouTube account has been infected with a self mailing worm and will be terminated in approx. 48 hours if malicious activities continue… Scan your account NOW with YouTubes online scanner to remove this dangerous threat from your computer and prevent further spread of this worm.

http://scanner01(dot)netai(dot)net/scan (hyperlink removed)

Since I was on my Mac Book I decided to click that link and this it what I found:
Oh no’s … a fake alert
Wow, my Mac just turned into a Windows box! …Fake scanner page.
Well, I haven’t seen this one before. MediaFire is hosting malware.
FYI – YouTube will never ever send you messages like the one mentioned above.

, , , ,

14 Responses to Fake YouTube Messages – Your Account is Infected!

  1. jamescv7 April 15, 2010 at 2:25 pm #

    Well i rated red on WOT has the website is a fake scanner/ Rogue Av / Fake AV

    Thanks for the warning.

  2. Sophos! April 15, 2010 at 2:52 pm #

    I received something similar the other day.
    Sophos blocked it though.

  3. Sophos! April 15, 2010 at 2:54 pm #

    And what happened to your site yesterday Matt?

  4. malwarekilla April 15, 2010 at 3:07 pm #

    @jamescv7 – sure, no problem, thanks for listing it.
    @Sophos! – I’m doing code upgrades on the site this week, so there may be a few…”whooops” moments.

  5. Sophos! April 15, 2010 at 3:24 pm #

    Oh ok then.

  6. jamescv7 April 15, 2010 at 3:34 pm #

    Finally WOT rated it red immediately cause a while ago it rated yellow-green.

  7. Chumm April 15, 2010 at 6:18 pm #

    Mediafire hosting malware? thats a first. Perhaps to lure the user into a false sense of security? Usually they host malware on there own servers..

  8. pranaygtr April 15, 2010 at 8:28 pm #

    Would that mean “s0m3b0de” account has possibliy been compromised?
    I blocked that user just incase. 😀
    Try and report the file, so it gets taken down.

  9. C. C. April 16, 2010 at 12:47 am #

    I know you all are referring to Mediafire, but take a look at this on RapidShare. It also has a video on YouTube. But 1st take a look at Virus Total scan results;
    Virus Total;
    http://www.virustotal.com/analisis/06a63bc72fc8c98a3159cda9f308cb206b5cc61dc4bb802147bfba318aeb9238-1271365143
    RapidShare;
    http://rapidshare.com/files/376298141/Club…y_Hack.exe.html
    YouTube

  10. C. C. April 16, 2010 at 2:41 am #

    Seems since my other post my email to RapidShare was read. The download has been removed. The YouTube video is still available, .

  11. TigerRaptorFX April 16, 2010 at 3:36 am #

    I noticed s0m3b0de has a video uploaded on YouTube with that fake AV. I just flagged the video as scams/fraud. So hopefully YouTube will be smart enough and remove it.

  12. C C April 16, 2010 at 3:49 am #

    I sent security at YouTube an email earlier today and they haven’t removed it so far. I think that whole Club Penguin channel is dedicated to hacking an malware,
    I also checked back at Malwarebytes where links where originally posted and the Rapidshare link is still working and the download is still available.at Rapidshare. I posted it on the Malware Domain List forums but they haven’t put it on the list.

  13. the croatian sensation April 16, 2010 at 10:42 pm #

    Matt,
    You need to test panda cloud free antivirus. You said you would a few months ago. pcmag.com ranked it better than both avira free and avast 5 free, please do a review of it, so we can truly no which is the best free av choice.

    Croatian

  14. Jacob April 22, 2010 at 12:16 am #

    Looks like the program was made by a skiddie… if you check the YouTube channel.

Leave a Reply