There is a new variant of Holar going around masquerading as a message from dispatch@mcafee.com. Why anyone would open a message from dispatch@mcafee.com and see that the message body contains pornography or stupidity and then STILL go on to execute the attachment is beyond me, but somehow it still happens.

Here are some details from the McAfee AVERT site :

AVERT is currently analyzing this threat. Details will be published as they become available. This threat is proactively detected as New MSVB P2P worm when using the 4266 DAT files with the 4.2.40 scan engine and scanning compressed executables (a default scan option).
This variant of the worm is very similar to previous variants. It is intended to propagate via email and sharing itself over P2P networks.

The worm consists of a 3-file sandwich:

DROPPER COMPONENT | PROPAGATION COMPONENT | SMTP LIBRARY
The dropper component is intended to drop and run the other components:

Propagation component: 56,614 bytes
SMTP library: 25,737 bytes
Strings within the dropper and propagation components suggest the worm is intended to arrive in a message with the following characteristics:

From: Dispatch@McAfee.com

Various subject lines and message bodies are carried within the worm...

...Attachment: Various filenames chosen from the following list (tailored to subject/message body):

Hot_Show.pif
Short_vClip.pif
Beauty_VS_Your_FaCe.pif
Endless_life.pif
Hearts_translator.pif
Shakiraz_Big_ass.pif
Sweet_but_smilly.pif
Broke_ass.pif
Lo0o0o0o0oL.pif
Gurls_Secrets.pif
Tedious_SeX.pif
Leaders_Scandals.pif
HaWawi_N_Hawaii.pif
Come_2_***.pif
Tears_of_Happiness.pif
White_AmeRica.pif
Famous_PpL_N_Bad_Setuations.pif
XxX_Mpegs_Downloader.pif
Teenz_Raper.pif
Real_Magic.pif
The_Truth_of_Love.pif
unfaithful_Gurls.pif
How_to_improve_ur_love.pif
AniMaL_N_Burning_Ladies.pif
Aint_it_Funny.pif
ToolAv01w32.pif