For those who don't trawl the AV sites or are not subscribed to any of the AV Newsletters/warning services, here is a current Cat 2 from symantec (Norton).
http://[email protected]

For AV information check the following:
http://www.f-prot.com/index2.html
http://www.mcafee.com/anti-virus/default.asp
http://securityresponse.symantec.com/
http://www.pandasoftware.com/
http://www.commandsoftware.com/virus/index.cfm
to list a small collection..

Watch out for the hoaxes.. some of the above sites have listings for the hoaxes or you could try:
http://hoaxinfo.com/
http://www.vmyths.com/

Cheers

W32.HLLW.GOP.G@mm is a mass-mailing worm that copies itself to the hard drive as %System%\WindowsAgent.exe. It also searches the network drives and copies itself to \Recycled\Notdelw.i.n.v.e.r.y.i.f.y.exe on any mapped drive on which it can find an operating system. Then, W32.HLLW.GOP.G@mm modifies the Win.ini file to run the worm at startup.


Type: Worm
Infection Length: 44,033 bytes
Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me
Systems Not Affected: Macintosh, OS/2, UNIX, Linux
When W32.HLLW.GOP.G@mm is executed, it does the following:


1. Copies itself as %System%\WindowsAgent.exe.

NOTE: %System% is a variable. The Trojan locates the System folder and copies itself to that location. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).

2. Creates the Drocerrbk.sys file, in which it stores stolen passwords.

3. Adds the value:

WindowsAgent %System%\WindowsAgent.exe

to the registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

4. Performs its mass-mailing routine. Mostly, the email message it sends will contain a subject and message in Chinese. The attachment will be a .bmp, .rtf, .doc, .txt, .gif, .jpeg, or .jpg file, which is taken from your computer.

To the original file name, the worm adds a second file extension, either .exe or .lnk. For example, if the original file name is Birthday pic.bmp, the name of the attachment will be Birthday pic.bmp.exe or Birthday pic.bmp.lnk.

The worm searches for email addresses in .htm and .html files, and in many different email mailbox files. After gathering all the email addresses the worm can find, it uses its own SMTP engine to send an email message that can be executed (on unpatched systems) when it is read by the recipient.

NOTE: The worm takes advantage of the IFRAME vulnerability that allows Microsoft Outlook to automatically execute attachments. Information on this vulnerability can be found at: http://www.microsoft.com/windows/ie/...8/default.asp.

5. Searches the network drives and copies itself to \Recycled\Notdelw.i.n.v.e.r.y.i.f.y.exe on any mapped drive on which it can find an operating system. Then, the worm sets that particular file to run at startup, by modifying the Win.ini file.