It says it interecepted several emails at the end of October targeting three Brazilian banks, but the technique may be used for other banks. Usually, "phishing" emails work by masquerading as legitimate emails from banks and other online services.
But one way of protecting yourself from these auto-phishing attacks is to disable Windows scripting, Message Labs notes.
The mails work by running a script which attempts to rewrite host files of the machine that it's targeting. The next time you attempt to log into an Internet site, you are automatically re-directed to a fraudulent one, allowing your login details to be appropriated. µ