Emerging threat reported by Symantec UK:
1100 UK Health Service machines infected with Qakbot:
http://www.symantec.com/connect/de/blogs/qakbot-steals-2gb-confidential-data-weekpol
P.S. Manual removal instructions:
1. Temporarily Disable System Restore (Windows Me/XP).
2. Update the virus definitions.
3. Reboot computer in SafeMode
4. Run a full system scan and clean/delete all infected files
5. Delete/Modify any values added to the registry.
Navigate to and delete the following registry entry:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrent VersionRun”[LEGITIMATE APPLICATION NAME]” = “”C:Documents And SettingsAll Users_qbothome_qbotinj.exe” “C:Documents And SettingsAll Users_qbothome_qbot.dll” /c [PATH TO LEGITIMATE APPLICATION]”
6. Exit registry editor and restart the computer.
7. In order to make sure that threat is completely eliminated from your computer, carry out a full scan of your computer using Avast AntiVirus and Antispyware Software like MBAM and SAS,
Damian