FYI…

- http://www.silicon.com/0,39024729,39166754,00.htm
16 April 2007 ~ "The largest proliferation of email virus attacks in more than a year is likely to have occurred last Thursday… two variations of the Storm Worm virus, which originally spread across the internet in January, have quickly driven global virus levels 60 times higher than their daily average… According to warning notices from Postini - as well as VeriSign, which has also been following the threat - clicking on the executable file in one of the new Storm Worm emails installs a rootkit with anti-security measures that mask the malicious software's presence from virus scans and shut down security programs that may be running. The virus then taps into a private peer-to-peer network where it can download new updates and upload personal information from the compromised computer. Additionally, the virus scans the machine's hard drive to locate email addresses to which it can replicate itself. Ultimately, computers infected with this virus become unknowing "zombies" in a botnet that are used to send out spam and further the attacks…"

Storm Worm -1-
- http://www.secureworks.com/research/threat…reat=storm-worm
Date: February 8, 2007
Author: Joe Stewart
"…The master component is run from a kernel rootkit driver (%windir%\system32\wincom.sys) …"

Storm Worm -2-
- http://www.f-secure.com/v-descs/email-worm…elatin_cq.shtml
Name: Email-Worm:W32/Zhelatin.CQ …
Date: April 08, 2007 …
"…The file name is wincom32.sys… The installed component has rootkit features: it hides its Registry keys and active process so that an anti-rootkit engine is needed to reveal them. In addition, this component drops a text file named wincom32.ini into the Windows System folder. This file contains a list of clients for the worm's peer-to-peer network…"

.