Tihs worm spreads via email and it is rapidly spreading. It was found on Aug.
16, 2009.
Upon execution the copies of worm,"rasor38a.dll" is created in window folder and "winpsd.exe" is created in Window system folder.
It retrieves email addresses from the infected system and spreads by sending email with attaching worm as subjected "Photos'.
The details are now analyzing, so the detected name I-Worm.Win32.Ratos.27136 can be changed.
How it spreads
Worm spreads via email with its own SMTP engine and the spreading via email spreads by retrieving email addresses from ifected system.