1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Look Like another new one

Discussion in 'Security and Privacy' started by BillyBob, 2002/06/20.

Thread Status:
Not open for further replies.
  1. 2002/06/20
    BillyBob Lifetime Subscription

    BillyBob Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    6,048
    Likes Received:
    0
    Morning All,


    Just got this warning this morning. This little nasty, after you execute
    it (meaning clicking on to open it. something we WON'T be doing,
    right?!?) attempts to disable your antivirus programs (which we all have
    a copy in our PC and keeping it up-to-date, right?!?). Oh well, on to
    the Bug de jour:


    Name: W32/Yaha-E
    Type: Win32 worm
    Date: 20 June 2002


    Description:


    W32/Yaha-E is a worm which spreads via email. The worm has its own
    SMTP client software and uses either an SMTP server found by examining
    the Windows registry or one from a list contained within the worm
    itself.


    The email sent by the worm is highly variable. The subject line of the
    email is created using a combination of words and phrases from the
    following list:


    searching for true Love
    you care ur friend
    Who is ur Best Friend
    make ur friend happy
    True Love
    Dont wait for long time
    Free Screen saver
    Friendship Screen saver
    Looking for Friendship
    Need a friend?
    Find a good friend
    Best Friends
    I am For u
    Life for enjoyment
    Nothink to worryy
    Ur My Best Friend
    Say 'I Like You' To ur friend
    Easy Way to revel ur love
    Wowwwwwwwwwww check it
    Send This to everybody u like
    Enjoy Romantic life
    Let's Dance and forget pains
    war Againest Loneliness
    How sweet this Screen saver
    Let's Laugh
    One Way to Love
    Learn How To Love
    Are you looking for Love
    love speaks from the heart
    Enjoy friendship
    Shake it baby
    Shake ur friends
    One Hackers Love
    Origin of Friendship
    The world of lovers
    The world of Friendship
    Check ur friends Circle
    Friendship
    how are you
    U r the person?
    Hi
    U realy Want this
    Romantic
    humour
    New
    Wonderfool
    excite
    Cool
    charming
    Idiot
    Nice
    Bullsh*t
    One
    Funny
    Great
    LoveGangs
    Shaking
    powful
    Joke
    Interesting
    Interesting
    Screensaver
    Friendship
    Love
    relations
    stuff
    to ur friends
    to ur lovers
    for you
    to see
    to check
    to watch
    to enjoy
    to share


    The message text begins:


    "Hi
    Check the Attachment ..
    See u "


    or


    "Attached one Gift for u.. "


    or


    "wOW CHECK THIS "


    The remainder of the message will resemble a forwarded email. The From
    and Subject fields of the forwarded message are also variable but the
    message will always contain the text:


    "This e-mail is never sent unsolicited. If you need to unsubscribe,
    follow the instructions at the bottom of the message.
    ***********************************************************


    Enjoy this friendship Screen Saver and Check ur friends circle...


    Send this screensaver from <web address> to everyone you consider a
    FRIEND, even if it means sending it back to the person who sent it to
    you. If it comes back to you, then you'll know you have a circle of
    friends.


    * To remove yourself from this mailing list, point your browser
    to:
    <web address>
    * Enter your email address (<sender's address>) in the field provided
    and click "Unsubscribe ".


    OR...


    * Reply to this message with the word "REMOVE" in the subject line.


    This message was sent to address <sender's address>
    X-PMG-Recipient: <sender's address>
    <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> "


    The attachment filename is made up of three parts- a name and two
    extensions.


    The name is chosen from:


    screensaver
    screensaver4u
    screensaver4u
    screensaverforu
    freescreensaver
    love
    lovers
    lovescr
    loverscreensaver
    loversgang
    loveshore
    love4u
    lovers
    enjoylove
    sharelove
    shareit
    checkfriends
    urfriend
    friendscircle
    friendship
    friends
    friendscr
    friends
    friends4u
    friendship4u
    friendshipbird
    friendshipforu
    friendsworld
    werfriends
    passion
    bullsh*tscr
    shakeit
    shakescr
    shakinglove
    shakingfriendship
    passionup
    rishtha
    greetings
    lovegreetings
    friendsgreetings
    friendsearch
    lovefinder
    truefriends
    truelovers
    f*cker
    loveletter
    resume
    biodata
    dailyreport
    mountan
    goldfish
    weeklyreport
    report
    love


    The first extension is chosen from:


    doc
    mp3
    xls
    wav
    txt
    jpg
    gif
    dat
    bmp
    htm
    mpg
    mdb
    zip


    The second extension is chosen from:


    pif
    bat
    scr


    The worm also creates a copy of itself in the Recycle folder with a
    name comprised of four random lower case characters. The path to this
    copy is then added to the following registry entry to ensure that the
    worm is run each time a program with an EXE extension is run:


    HKLM\exefile\shell\open\command\default


    Two files are created in the Windows folder. One has a DLL extension
    and an eight character name created from the same four characters used
    for the copy of the worm. This file contains a list of email addresses
    found on the infected computer. The second file has the same name as
    the copy of the worm and a TXT extension. This is a simple text file
    containing the text "iNDian sNakes pResents yAha.E ".


    The worm will attempt to disable security software by terminating any
    of the following processes:


    SCAM32
    SIRC32
    ZONEALARM
    LOCKDOWN2000
    AVP.EXE
    CFINET32
    CFINET
    SAFEWEB
    WEBSCANX
    ANTIVIR
    MCAFEE
    NORTON
    FP-WIN
    IOMON98
    PCCWIN98
    F-PROT95
    F-STOPW
    PVIEW95
    NAVWNT
    NAVRUNR
    NAVLU32
    NAVAPSVC
    SYMPROXYSVC
    RESCUE32
    NISSERV
    ATRACK
    IAMAPP
    LUCOMSERV
    NAVW32
    NAVAPW32
    VSSTAT
    VSHWIN32
    AVSYNMGR
    AVCONSOL
    WEBTRAP
    POP3TRAP
    PCCMAIN
    PCCIOMON


    When the worm is first run it will imitate a screen saver by
    repeatedly displaying the following messages on the screen in various
    colours:


    U r so cute today "! "!
    True Love never ends
    I like U very much!!!
    U r My Best Friend


    A copy of the attachment in base64 encoded format is created in the
    folder C:\Windows\Temp with the filename kitkat.
     
  2. 2002/06/20
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    Great post BillyBob!
    Just for added info from Symantec .

    Daizy
     

  3. to hide this advert.

  4. 2002/06/20
    BillyBob Lifetime Subscription

    BillyBob Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    6,048
    Likes Received:
    0
    Thanks should really go to Road Runner WebMaster.

    Ink was not even dry on E-mail and three machines were receiving AV updates.

    BillyBob
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.