View Single Post
Old 05-29-2010, 06:55 AM
  #15  
patricej
Administrator
 
patricej's Avatar
 
Join Date: Nov 2006
Location: Southeast Georgia, USA
Posts: 9,305
Default

on a Vista system, it saves itself to

c:\users\[whatever your username is]\app data\Local\Temp\Low

on my computer it named itself 9.525560894510851E8.exe

i use symantec endpoint protection. the virus slipped through far enough to generate the fake message. however, symantec detected it when i ran a quick scan, and told me where it was. i could have used the "delete" option on the scan, but deleted it manually and then emptied my recycle bin.

if you're into techno-gobbledygook, here's a detailed explanation:
http://securityresponse.symantec.com...101013-3606-99
patricej is offline