New Vundo
This was undetected with Bitdefender and ClamAV. McAfee Webimmune detected it as Vundo. I found it in c:\windows\system32 on a Windows XP SP2 system, hooked in via a Winlogin notify registry key. It originally had a .dat extension. The usual vundo removal tricks (use proces###plorer to suspend just about everything, then…