Here's a war story a friend sent me about the Worm.ExplorerZip email virus that's floating around:
Our War Story about his virus just got worse. It seems that someone opened the file on a machine that had mapped drives to several Production servers. Even though this person had only "Change" access to the files on the server the Virus deleted ALL THE CONTENT OF EVERY FILE on EVERY SERVER! THEY DO *NOT* NEED DETELE ACCESS TO WIPE A FILE TO 0 BYTE LENGTH! We are now look at a WORLDWIDE shutdown of several key systems. Several of the e-mail systems have crashed and most of our File Server Clusters have been shutdown to stop this "Wiping of files" from happening again. Worse part is the Virus continues scanning ALL DRIVES (C through Z) on the infected machine until they are cured. Each time we bring up a server we get swamped with requests to set files to 0 byte lengths. If you have not encountered this virus yet, listen closely! It is perhaps that worse virus we have ever seen. We estimate that over 500 GIGS YES GIGS of data on our Product systems have been deleted across the enterprise. Even worse is that the backup machines cannot be brought online until all clients have been cleaned. For they are just Wiped Clean within seconds of being brought online.