Threat description



On 12th of Februaru 2003 we received a report from a customer that he had got a suspicious message. The message looked like that:

YOU HAVE RECEIVED A VALENTINES DAY E-CARD!  Greetings,  Someone has sent you a Valentines Day E-Card ::: a virtual postcard from  To view your card please click the link below :    ----------------------------------------------------------------------------------  This card was provided by Copyright 2003 All Rights Reserved  

The link pointed to the page that provided the CARD.EXE file for download. The file contained an animated Valentines Day greeting card that looked like that:

The animated greeting card was installed on a hard drive and the uninstallation program for it was provided. But at the same time, the CARD.EXE file hiddenly dropped 3 adware/spyware files in Windows System folder:


These files are not malicious, they are adware/spyware components that help its makers to collect information about computer user's habits and provide him with appropriate advertisment. No personal information about a user is collected.

As these adware components were hiddenly dropped to computers without a user seeing and accepting a licence agreement, we consider the CARD.EXE file to be malicious. We added detection for this file into our anti-virus databases.

If you got the message mentioned above, please do not follow the link, do not download and run the CARD.EXE file.


Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Submit a Sample

Suspect a file or URL was wrongly detected?
Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info