Next one in the Bin Laden-game row

Kaspersky
This worm uses the Internet instant messaging system ICQ to spread via the Internet.

The worm sends ICQ users a message with a URL, which is linked to a file which contains procedures to automatically download and execute the malicious component of the worm on the victim computer.


Propagation

On connecting to the site http://www.jokeworld.xxx/xxx.html
(x here is used to replace certain characters) the CHM-exploit-a is used. The result of this is that a specially constructed CHM file is automatically executed on the victim computer. This file contains another file named 'ie****er.html'; this file contains TrojanDropper, a type of Trojan written in script language. This Trojan extracts a file named WinUpdate.exe from itself to a range of system directories.
...