Hey All: A friend of mine sent me an install icon for an app calling itself "msnplus8final". Being a plus user for a long time this began many bells ringing - but also being inquisitve (stupid sometimes) I installed to see what it was.
WORM. My zonealarm went frantic, gave me the name of the file that was calling itself kernal32.exe, yet it's wasn't there and is changing it's name.
WORM. Fortunately through ZA I was able to kill this process. Anyone else got info on this nefarious item?? It's making the rounds via peer to peer, and the url for downloading it is not a site, just a link. This nefarious item is hiding in system32 under the name of C:\WINDOWS\system32\ewhzrrl, according to my ZA, but just try to find it to remove it. HAH. I have put a screenshot(jpeg) of the install icon here as well so all can see what it looks like.
Well, trust Norton - found this nefarious little thing - W32.Kelvir was the worm, and it is gonzo. Rock on all.