Witty - "highly destructive"
http://www.ravantivirus.com/virus/showvirus.php?v=213
http://www.f-secure.com/weblog/
http://www.lurhq.com/witty.html
http://www.f-secure.com/v-descs/witty.shtml
Variations of witty appeared
http://isc.incidents.org/diary.html?date=2004-03-20
from there:
"The latest version of BlackIce, released this Wednesday, is the only version which is likely safe. It is identified by the letter 'g' at the end of its version. For example:
BlackIce 3.6 ccf and BlackIce 3.6 ecf are vulnerable
BlackIce 3.6 ccg and BlackIce 3.6 ecg are likely safe
Other ISS products may be vulnerable as well. Please refer to ISS for details (see end of this post for links). The Witty worm will only effect some of the vulnerable versions. 3.5 appears to be not vulnerable to the worm, even though the PAM module has the bug. Version 3.6 ccf is confirmed to be vulnerable."