The worm also modifies the registry to disable Registry Editor and Task Manager.
It also changes the Internet Explorer (IE) home page to;
http://(BLOCKED)ecoolpics.com.
This worm propagates via Yahoo! Messenger, AOL Instant Messenger (AIM), Windows Live Messenger or Windows Messenger by sending an instant message to all the contacts of an active user. This message contains a link to a remote copy of itself. When the recipient clicks the link, a copy of this worm is downloaded and executed on the recipients' system.
The details of the message sent out by this worm are:
http://(Blocked)thecoolpics.com/hot.jpg :x "hot pics this week " http://(Blocked)thecoolpics.com/hot.jpg :x" ";) 1 of my vacation pictures " http://(Blocked)thecoolpics.com/vacation2.jpg <:-P " "Screenshot of new windows version _ Windows Vista " http://(Blocked)thecoolpics.com/vista.jpg so cool :D" "Images shot in Iraq _ The war will never end " http://(Blocked)thecoolpics.com/Iraqwar.jpg << :(" "oh my god , i've won a 20000 usd lottery :O " http://(Blocked)thecoolpics.com/mylottery.jpg << " "never click into the links like something in this image " http://(Blocked)thecoolpics.com/dontclick.jpg #:-S !!! " ":( the page cannot be displayed " http://(Blocked)thecoolpics.com/error.jpg Something was wrong !!! Check it again and tell me later. THanks" "My pics " http://(Blocked)thecoolpics.com/mypics.jpgb-( << " "Miss World 2006: " http://(Blocked)thecoolpics.com/MissWorld.jpg !!" "Do you realize who is in this image: " http://(Blocked)thecoolpics.com/who.jpg . Just think for a moment and tell me soon ;))"
The worm takes advantage of a vulnerability in Microsoft Data Access Components (MDAC) Function as explained in Microsoft Security Bulletin MS06-014.
Upon successfully exploitation of the the said vulnerability, it allows the worm to connect to the website http:// www.(Blocked)ecoolpics.com/INDEX.HTML to download and execute an embedded script.
It also attempts to connect to the following website to download and execute some malicious files named en.exe and link-en.exe which are copies of itself.
Proland
Software is the developer of Protector Plus range of antivirus software
packages. Protector Plus 2007 is available for Windows Vista, Windows 95/98/Me, Windows
XP, Windows NT/2000/2003 servers and workstations, MS-Exchange 2000/2003, MS-DOS
and NetWare servers.
Protector Plus range of antivirus products
offer on-line virus detection and removal. All the packages have the ability
to detect and isolate all types of viruses, trojans, worms and other types
of malware.
These products are updated on a continuous basis and the latest upgrades
for all the platforms are made available for downloading from this site.