This story has been running in the spyware community for a few weeks now.
More info can be found here:
http://www2.spywareinfo.com/category/news/cws-id-theft/For those of you that look at HijackThis logs now and again, if you see this line in a log:
O4 - HKLM\..\Run: [load32] C:\WINDOWS\System32\winldra.exe
please contact your nearest Moderator or send the victim a personal message referrring them to the SpywareInfo link above.
Then tell them to install a firewall and block EVERYTHING trying to call out.