QUOTE(Merlyn @ Aug 10 2008, 12:09 AM)

Thanks Merlyn. It appears the attack is unabated, checking the mailbox of the account I am receiving these on, over VPN (unfortunately I can't get the headers over Outlook Web Access to report them). Some (elsewhere) have commented that the numbers are tapering off but I would guess that's just some filtering kicking in.
CNN is not coping at all well with this (so yeah, to the OP, help them, definitely REPORT the things if you can). Their (CNN) advice - at the top of
http://behindthescenes.blogs.cnn.com/2008/...nncom/#comments was late, incomplete (didn't spell out the hazard) and in the user comments (a blog which *reviews* posts) they even allowed the posting of a live link to one of the infector sites! (Fortunately that infector page is gone at the moment but did the website's owner close the vulnerability? If not the exploit page can be restored in an instant.) For Pete's sake.
If ever we wonder if we do any good 'here' just have a look at that comment blog and so remind yourself what the average, uncommited (even when aroused), internet user is like. Pitiful. And the manifest inadequacies of businesses (even those in the communications business) - or CNN at least - to deploy any sort of realistic and timely response when they are 'used' in attack. I mean, CNN is being harmed by this too, have they never forseen the possibiity?
Oh yeah, to all, don't go following "Microsoft.com's" emailed invitation to update IE7. Unrelated (it looks) but yet another spoof pointing to Lord knows what at some definitely non-MS website target (along with some genuine MS "backgound" links, like "unsubscribe"). "You are receiving this e-mail because you subscribed to MSN Featured Offers." - what nonsense. Seen amongst all my "CNN alerts" (as they are now), along with messages from those helpful "UPS Postal Service" people (unzip attached invoice and mosey on down to our office to retrieve your package - 12,000 miles away but what the heck) and an eCard awaiting my download, just to cheer me up.
Wow, as said elsewhere, the botnet recruiment thing is really picking up. Please report them.