Bagel
"We've received a few reports that readers are receiving what appears to be a new version of the Bagel virus in email this morning. The attachments (so far) appear to be named as a single digit number zip file (eg: "5.zip" or "7.zip") or as a string (eg: "Be_not_jealous.zip") with a payload of "16_05_2005.exe" or "19_04_2005.exe". The .zip file is approximately 18k and is 36352 bytes when extracted. Upon execution, this file will be copied to C:\WINDOWS\System32\winshost.exe and will then fetch another 11k file and place it in C:\WINDOWS\System32\wiwshost.exe The registry key HKLM/Software/Microsoft/Windows/Current Version/Run is then updated to execute this winshost.exe file at boot.
Mytob
"We're also getting reports of a new Mytob virus. It appears that this one may be exploiting the MS05-016 vulnerability"
Internet Storm Center
"We've received a few reports that readers are receiving what appears to be a new version of the Bagel virus in email this morning. The attachments (so far) appear to be named as a single digit number zip file (eg: "5.zip" or "7.zip") or as a string (eg: "Be_not_jealous.zip") with a payload of "16_05_2005.exe" or "19_04_2005.exe". The .zip file is approximately 18k and is 36352 bytes when extracted. Upon execution, this file will be copied to C:\WINDOWS\System32\winshost.exe and will then fetch another 11k file and place it in C:\WINDOWS\System32\wiwshost.exe The registry key HKLM/Software/Microsoft/Windows/Current Version/Run is then updated to execute this winshost.exe file at boot.
Mytob
"We're also getting reports of a new Mytob virus. It appears that this one may be exploiting the MS05-016 vulnerability"
Internet Storm Center