Good spot AB.
Lake Sagaris,
Let's have a look..Download 'Hijack This!'. Unzip, doubleclick HijackThis.exe, and hit "Scan".
When the scan is finished, click "Save Log", and copy and paste it in a reply.
http://www.spywareinfo.com/~merijn/files/HijackThis.exe
UPDATE: W32.Novarg.A@mm
It opens a set of ports on the victim's computer and adds several files.
%Windir%\shimgapi.dll
%Windir%\taskmon.exe
If you see an O4 entry in an HJT log for this:
%Windir%\taskmon.exe (Windir is the Windows directory - Windows/Winnt.)
The victim is probably infected. Symantec should be able to clean it soon, and F-Prot's got beta definitions out.
(Note: There is _NO_ legitimate C:\winnt\taskmon.exe in Windows 2K/XP)
Also, it runs through the standard file-search-for-e-mail-addresses routine. Its DOS attack against SCO will last from 02/01 from 02/12, as there apparently is a time limit hardcoded into the virus.
(Information from Symantec's site.)
How to backup the registry:
http://vil.nai.com/vil/SystemHelpDocs/RegBack.htm
How to edit the registry:
http://vil.nai.com/vil/SystemHelpDocs/Regedit.htm