The Storm Botnet is infamous for it's delivery of "pump & dump" stock spam. In the past we've seen html, images and even mp3 formats used to bypass filtering. What better way to avoid e-mail filtering than by avoiding the use of e-mail?
The Botnet operator is now delivering web browser pop ups with similar stock tips to users of PC's that have been infected by the Storm Worm! The Secureworks team posted a screen shot of one of the pop-ups.
It's an interesting tactic since it draws attention to the fact that a PC has already been compromised by the worm and the owner may decide to fix it. On the other hand, it's more likely that it would be looked at than a spam e-mail which runs an incredibly high risk of being caught by anti-spam or just deleted from an inbox.