
Kaspersky Lab has identified <A HREF="http://www.viruslist.com/en/weblog?weblogid=208187485">a new malware scheme taking hold.</A> To start, a user's computer is infected with a piece of malware called MonaRonaDona. Rather than hiding itself on the machine like most malware, this makes itself highly visible to the user, a probable attempt to get people to Google solutions for MonaRonaDona. Once a user takes that step, you are led to a site called Unigray Antivirus that purports to be a legitimate antivirus company.
A little digging revealed that Unigray has only been a registered Web site for two weeks--an immediate red flag. When you run a scan of your computer using Unigray's technology, it pops up with completely random infections, calling them all a form of the MondaRonaDona malware. Upon closer inspection, Kaspersky analysts uncovered that Unigray is only capable of removing one piece of malware from a user's system--you guessed it, the MonaRonaDona malware for a fee of $39.90. This leaves very little doubt that the same group is behind both MonaRonaDona and Unigray.