In the past few months, Email-Worm.Win32.Zhelatin always masquerades as “ecard.exe” in the lots of spams.

Since last night, the file name has been changed. The latest file name is “msdataaccess.exe”. Everyone should be careful.

msdataaccess.exe