The worm also modifies the registry to disable Registry Editor and Task Manager.
It also changes the Internet Explorer (IE) home page to;
http://(blocked)vantinhyeu.info
This worm propagates via Yahoo! Messenger by sending an instant message to all the contacts of an active user. This message contains a link to a remote copy of itself. When the recipient clicks the link, a copy of this worm is downloaded and executed on the recipients' system.
The details of the message sent out by this worm are;
Chung ta hay cung len an hanh dong cua be crys, ko de nhung blog ban ton tai http://{BLOCKED}og.360.yahoo.com/blog-lgnzAww8fqlE9ZWuADs-?cq=1&p=534
Bo oi! Co biet gi chua ha?Cai nay hay lam a nha http://www.{BLOCKED}vantinhyeu.info
Toi yeu Viet Nam http://{BLOCKED}og.360.yahoo.com/blog-lgnzAww8fqlE9ZWuADs-?cq=1&p=534
cau noi hay nhat danh cho 2 nguoi iu nhau http://www.{BLOCKED}vantinhyeu.info
Di xe dap dam chet nguoi =)) http://www.{BLOCKED}vantinhyeu.info
Loi to tinh dau tien cua tui :x http://www.{BLOCKED}vantinhyeu.info
chao ban, lau lam ko gap, ban nhan tin lai cho minh nhe
buc thu tinh hay nhat http://www.{BLOCKED}vantinhyeu.info >:D<
chao ban, lau lam ko gap, ban nhan tin lai cho minh nhe
Biet yeu la sai lam, sao ta cu yeu dai kho http://www.{BLOCKED}vantinhyeu.info
Lan dau tien len...giuong =)) =)) http://www.{BLOCKED}vantinhyeu.info
Hay noi khong voi nhung blog ban, du ban o mien Bac hay Nam van la nguoi con cua VN http://{BLOCKED}og.360.yahoo.com/blog-lgnzAww8fqlE9ZWuADs-?cq=1&p=534#comments
It also attempts to connect to the following website to download and execute some malicious files.
http://{blocked}vantinhyeu.info/enet.exe
The worm tries to terminate some of the security related processes.
Proland
Software is the developer of Protector Plus range of antivirus software
packages. Protector Plus 2007 is available for Windows Vista, Windows 95/98/Me, Windows
XP, Windows NT/2000/2003 servers and workstations, MS-Exchange 2000/2003, MS-DOS
and NetWare servers.
Protector Plus range of antivirus products
offer on-line virus detection and removal. All the packages have the ability
to detect and isolate all types of viruses, trojans, worms and other types
of malware.
These products are updated on a continuous basis and the latest upgrades
for all the platforms are made available for downloading from this site.