Threat Description



Aliases: Adolff, AdwareDropper, AdwareDroper-A, Adware Dropper, Valentines Day E-Card, W32/Adware.Valentine
Category: Malware
Platform: W32


On 12th of Februaru 2003 we received a report from a customer that he had got a suspicious message. The message looked like that:

YOU HAVE RECEIVED A VALENTINES DAY E-CARD!  Greetings,  Someone has sent you a Valentines Day E-Card ::: a virtual postcard from  To view your card please click the link below :    ----------------------------------------------------------------------------------  This card was provided by Copyright 2003 All Rights Reserved  

The link pointed to the page that provided the CARD.EXE file for download. The file contained an animated Valentines Day greeting card that looked like that:

The animated greeting card was installed on a hard drive and the uninstallation program for it was provided. But at the same time, the CARD.EXE file hiddenly dropped 3 adware/spyware files in Windows System folder:


These files are not malicious, they are adware/spyware components that help its makers to collect information about computer user's habits and provide him with appropriate advertisment. No personal information about a user is collected.

As these adware components were hiddenly dropped to computers without a user seeing and accepting a licence agreement, we consider the CARD.EXE file to be malicious. We added detection for this file into our anti-virus databases.

If you got the message mentioned above, please do not follow the link, do not download and run the CARD.EXE file.


Automatic action

Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.


Detailed instructions for F-Secure security products are available in the documentation found in the Downloads section of our Home - Global site.

You may also refer to the Knowledge Base on the F-Secure Community site for further assistance.

Technical Details:F-Secure Anti-Virus Research Team; February 13th, 2003


Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Now

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More