[email protected] : A new worm to watch for, spreads itself via email and peer to peer networks. It has it’s own SMTP engine and scans local files for email addresses. It uses the TLD (top level domain) to determine which language to send itself in. The following registry key is created by the worm: HKEY_LOCAL_MACHINESOFTWAREMicrosoft_Hazafibb
[email protected]: Does not send itself, it uses infected machines to send political SPAM in German. The worm creates the following file: winhlpx32ll.exe
As always please keep your anti-virus files up to date. If you believe you have launched either of these worms clean your system immeditely with the latest anti-virus signatures.