This worm spreads via the Internet as the files attached to infected messages.
Contents of infected messages:
Message header: "GREAT NEW YEAR OFFER FROM PAYPAL.COM!"
Attachment name: pp-app.zip
To send infected messages the worm uses its own SMTP library.
To find email addresses to send messages to, the worm looks for address lines which contain the predefined suffixes:
but does not search for addresses in files with the following extensions: jpg, gif, exe, dll, avi, mpg, mp3, vxd, ocx, psd, tif, zip, rar, pdf, cab, wav, com.
When executed, the worm displays a dialogue box on screen which asks for PayPal credit card details.
Data entered is stored in 'c:\tmpny3.txt' and is then sent on to the author of the worm.
The worm opens port 5555 to listen for commands.
The worm changes the home page in Internet Explorer to a link containing pictures of George Bush:
Use antivirus (also check How To Remove section)Startup Optimizer to remove it from startup.