This one seems interesting. Rather than going through your address book, it seems to got through your browser cache. So any sites that you have visited that are cached in your browser temporary folder (this happens automatically until it times out or you clear it). It looks for addresses (that almost every site has in a contact page). This may be for IE only based on Symantec.
This is bad for a couple of reasons, people with Eudora or another MAPI compliant emailer are not immune (like in previous viruses that only go through your Outlook address book) and it seems to do some wild stuff including copying keystrokes.
There is additional information on symantec's site (www.symantec.com)
|