Greetings all,
I managed to download this malware myself - in a file with suffix '.nfo.exe' (is there anyone dumb enough these days to _still_ be obfuscating their filetypes?)
Anyhoo, I went to Jotti's malware scanner
CODE
http://virusscan.jotti.org/
& upped it for analysis - here's what I got (v. funny

) :
File: bleurgh.nfo.exe
Status: INFECTED/MALWARE
MD5: afc222f034bade5041cbee93dfd4fbae7
Packers detected: -
Scanner results
------------------
Scan taken on 31 May 2008 04:34:27 (GMT)
A-Squared...........................Found.........Backdoor.Win32.Kbot.by
AntiVir.................................Found.........TR/Crypt.XDR.Gen
ArcaVir.................................Found.........Adware.Searchit.J
Avast...................................Found.........Win32:Zbot-VQ
AVG Antivirus.......................Found.........nothing
BitDefender..........................Found.........nothing
ClamAV................................Found.........Trojan.Kbot-34
CPsecure.............................Found.........BackDoor.W32.Kbot.by
Dr.Web................................Found.........nothing
F-Prot Antivirus.....................Found.........nothing
F-Secure Anti-Virus...............Found.........Backdoor.Win32.Kbot.by
Fortinet................................Found.........nothing
Ikarus...................................Found.........Backdoor.Win32.Kbot.by
Kaspersky Anti-Virus.............Found.........Backdoor.Win32.Kbot.by
NOD32..................................Found.........probably a variant of Win32/Agent (probable variant)
Norman Virus Control............Found.........W32/Kbot.X
Panda Antivirus.....................Found.........nothing
Sophos Antivirus...................Found.........nothing
VirusBuster...........................Found.........nothing
VBA32...................................Found.........Backdoor.Win32.Kbot.by
Kinda says it all really, eh?
Oddly though, although Jotti's version of AVG reported 'nothing', it was exactly _that_ (AVG - my version, anyway) that flagged the file as 'Win32/Heur'...
Well, I just _had_ to get that little nuggette off my chest - & that's that.
Cheers all,
zarathustra