Got one too a few hours ago. Mark Dalal's email address noted as sender in the mailinfo (while the sender in my reader gave a "noreply" + my isp as sender). Whether it means Mark is infected, or just got his address stolen I don't know. (The same password that others reported). Just deleted it. My McAfee virus scan didn't find anything wrong with the attached "Message.zip"-file.
Lasse At http://securityresponse.symantec.com/avcenter/venc/data/[EMAIL PROTECTED] where there is more info on it, says: [EMAIL PROTECTED] is a worm that spreads by email and steals information from a user's machine. The email has the following characteristics: Subject: your account [random string] Attachment: message.zip The threat captures information from certain windows on a user's desktop and emails it to specific mail addresses. This threat takes advantage of known vulnerabilities: MS02-15 and MS03-14. A Microsoft patch is located at: http://www.microsoft.com/windows/ie/downloads/critical/330994/default.asp. We encourage system administrators to apply the Microsoft patch to prevent infection by this worm. The worm is packed with UPX. Virus definitions with a version number of 50801r, also known as August 1, 2003 rev 18, or greater will detect this threat. Symantec Security Response has created a tool to remove [EMAIL PROTECTED] "

