
W32.YAHA.F@MM
SPREADING IN THE WILD
Virus Name : W32.Yaha.F@mm
Alias : I-Worm.Lentin.g,
W32/Yaha-E, WORM_YAHA.G, Yaha.E
Virus type : Internet
worm
Threat
level : Medium
Virus
details :
Yaha.E aka W32.Yaha.F@mm is
a mass mailing worm uses e-mail addresses stored
in Windows Address book and also collects
addresses from .ht* files to distribute infected
messages. It also spreads through MSN messenger
list, ICQ list and Yahoo pager list.
W32.Yaha.F@mm
arrives as an e-mail attachment with random
message subject and message body. The SMTP server used to
send the emails is chosen either from the
registry or from the following list inside the
worm body.
The worm
uses the following combination of words as subject
searching
for true Love
you care ur friend
Who is ur Best Friend
make ur friend happy
True Love
Dont wait for long time
Free Screen saver
Friendship Screen saver
Looking for Friendship
Need a friend?
Find a good friend
Best Friends
I am For u
Life for enjoyment
Nothink to worryy
Ur My Best Friend
Say 'I Like You' To ur friend
Easy Way to revel ur love
Wowwwwwwwwwww check it
Send This to everybody u like
Enjoy Romantic life
Let's Dance and forget pains
war Againest Loneliness
How sweet this Screen saver
Let's Laugh
One Way to Love
Learn How To Love
Are you looking for Love
love speaks from the heart
Enjoy friendship
Shake it baby
Shake ur friends
One Hackers Love
Origin of Friendship
The world of lovers
The world of Friendship
Check ur friends Circle
Friendship
how are you
U r the person?
Hi
U realy Want this
Romantic
humour
New
Wonderfool
excite
Cool
charming
Idiot
Nice
Bullshit
One
Funny
Great
LoveGangs
Shaking
powful
Joke
Interesting
Interesting
Screensaver
Friendship
Love
relations
stuff
to ur friends
to ur lovers
for you
to see
to check
to watch
to enjoy
to share
The
message body will be one of the following
"Hi dear
check the attach
see u"
"Hi
Check the Attachment ..
See u"
"Attached one
Gift for u.."
"wOW CHECK
THIS"
"Check the
attachment"
"See the
attachement"
"Enjoy the
attachement"
or
"More details
attached"
The remainder of
the message may contain the following text
resembling a
forwarded email. The From and Subject fields of
the forwarded message are
also variable but the message will always contain
the text:
"This e-mail
is never sent unsolicited. If you need to
unsubscribe,
follow the instructions at the bottom of the
message.
***********************************************************
Enjoy this
friendship Screen Saver and Check ur friends
circle...
Send this
screensaver from <web address> to everyone
you
consider a FRIEND, even if it means sending it
back to the person
who sent it to you. If it comes back to you, then
you'll know you
have a circle of friends.
* To remove
yourself from this mailing list, point your
browser to:
<web address>
* Enter your email address (<sender's
address>) in the field provided
and click "Unsubscribe".
OR...
* Reply to this
message with the word "REMOVE" in the
subject line.
This message was
sent to address <sender's address>
X-PMG-Recipient: <sender's address>
<<<>>> <<<>>>
<<<>>> <<<>>>
<<<>>> <<<>>>
<<<>>> <<<>>>
<<<>>>
<<<>>>"
The attachment
filename name will be one of the following. The
attachment name will contain two extenstions
screensaver
screensaver4u
screensaver4u
screensaverforu
freescreensaver
love
lovers
lovescr
loverscreensaver
loversgang
loveshore
love4u
lovers
enjoylove
sharelove
shareit
checkfriends
urfriend
friendscircle
friendship
friends
friendscr
friends
friends4u
friendship4u
friendshipbird
friendshipforu
friendsworld
werfriends
passion
bullshitscr
shakeit
shakescr
shakinglove
shakingfriendship
passionup
rishtha
greetings
lovegreetings
friendsgreetings
friendsearch
lovefinder
truefriends
truelovers
fucker
loveletter
resume
biodata
dailyreport
mountan
goldfish
weeklyreport
report
love
The first extension is
chosen from doc, mp3, xls, wav, txt, jpg,
gif, dat, bmp, htm, mpg, mdb, zip. The
second extension is chosen from pif, bat,
scr.
If the infected e-mail
attachment is executed, it runs as a scren saver
and also copies itself to C:\recycled in four
letter random file name with hidden attribute. It
also displays the following text in different
colours.
I like U
very much!!!
Ur My Best Friend!!
True Love never ends
U r so cute today #!#!
U r My Best Friend
No Configuration is availabile Now
After
that it modifies the registry to load
automatically whenever an "EXE" file is
executed. The registry key modified will be
HKEY_CLASSES_ROOT\exefile\shell\open\command
In some cases it uses
IFRAME vulnerability to infect. When the user views the
e-mail the embedded code is executed
automatically and it drops the virus. Microsoft
released security patches to close this security
hole. If you haven't installed, you can get a
copy at http://www.microsoft.com/windows/ie/download/critical/Q290108/default.asp
When active in memory it
will disable antivirus programs. Yaha worm has
the ability to spread through network.
Yaha.E
variant drops a text file in Windows folder with
following text.
<<<>>>
<<<>>> <<<>>>
<<<>>> <<<>>>
<<<>>> <<<>>>
<<<>>> <<<>>>
<<<>>>
iNDian sNakes pResents yAha.E
iNDian hACkers,Vxers c0me & w0Rk wITh uS
& fUCk tHE GFORCE-pAK shites
bY
sNAkeeYes,c0Bra
<<<>>> <<<>>>
<<<>>> <<<>>>
<<<>>> <<<>>>
<<<>>> <<<>>>
<<<>>> <<<>>>
Yaha.E aka W32.Yaha.F@mm worm doesn't
contain any destructive payload. But if
you have deleted the worm file before fixing the
registry entries your applications will NOT work.
In that case manual registry modifcation
will be required. Instead of deleting the worm
file manually, you can use Solo trial version to
remove Yaha.E worm safely.
How can I protect my
system?
Solo has incorporated W32.Yaha.F@mm in its signature file to
protect users from this worm attack. Solo
antivirus registered users are already protected
from this worm. Make sure that you have installed
registered version of Solo Antivirus to protect
your system from all virus threats.
How
to remove this worm?
If
you are already infected with this worm, you can
remove it from your computer using Solo Antivirus
software. Solo antivirus can detect and
remove W32.Yaha.F@mm safely. Use the
following link to Download 30 day trial
version of Solo antivirus
to
remove viruses from your computer.

Solo anti-virus not only
scans for all viruses, it contains a unique System
Integrity Checker to protect you from
New Internet Worms, Backdoors and
malicious VB, Java Scripts. It also
effectively removes all existing Internet Worms,
File viruses, malicious VBS, Java scripts,
Trojans, Backdoors, boot sector, partition table
and macro viruses.
You can
purchase Solo antivirus using the link 

|