We got a Chinese Worm virus at work. It was the one that compromises a Solaris box and uses that box to randomly search the available internet for Windows based systems that have IIS loaded on them. It then uses a known exploit, which we didn't have patched at the time, to replace all HTML files in the root and INetPub directorys w/ it's own files.
The webpages it replaced it with said F*ck Chinese Government and F*ck USA Government.
Had to be Chinese b/c a US citizen would've said US and not USA Just my opinion. Oh and also the fact that we traced it back to the butthole's street address in China