We were hit with this virus last week. It infected 1 NT 4.0 sp 6a server and 15 workstations (Win95, Win98 and WinXP). It did NOT seem to spread via shares or email. However, most of the workstations that became infected ran programs that were on the NT 4.0 server. The virus seems to infect valid exe files, i.e., winword.exe, spooler.exe, etc.
Only fix was to rebuild all workstations and the server. During this process we discovered the core virus exe file which among other things would create the UssaShohhdi.* file.
We sent the exe to our anti-virus company, McAfee and within 5 hours they identified it as W32/Shoder.a@MM and provided us with a EXTRA.DAT (supplemental virus ID file). We have applied the EXTRA.DAT to some workstations that were infected and it is cleaning the files.
McAfee still has not updated their virus library with the W32/Shoder.a@MM virus. Also, a google search does not turn up anything with that name yet.
Interestingly, in the code of the virus it contains a text that is a rant about America, government, and is very negative against President Bush.
Hope this information is helpful to others and good luck.