Win32/Yaha [Threat Name] go to Threat
Win32/Yaha.N [Threat Variant Name]
Category | worm |
Size | 34304 B |
Aliases | Email-Worm.Win32.Lentin.i (Kaspersky) |
W32.Yaha.K@mm (Symantec) | |
W32/Yaha.k@MM (McAfee) |
Short description
Win32/Yaha.N is a worm that spreads via e-mail. The file is run-time compressed using UPX . The worm terminates various security related applications.
Installation
When executed, the worm copies itself into the folder:
- %system%
with the following file names:
- WinServices.exe
- nav32_loader.exe
- tcpsvs32.exe
In order to be executed on every system start, the worm sets the following Registry entries:
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
- "WinServices" = "%system%\WinServices.exe"
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
- "WinServices" = "%system%\WinServices.exe"
- [HKEY_LOCAL_MACHINE\Software\Classes\exefile\shell\open\command]
- "(Default)" = ""%system%\nav32_loader.exe""%1"%*"
Spreading via e-mail
E-mail addresses for further spreading are searched for in local files with one of the following extensions:
- .*ht*
- .*HoTMAil*
Also the e-mail addresses are searched for in the following program(s):
- MSN Messenger
- Yahoo Pager
The worm uses the addresses found in Windows Address Book, too.
Subject of the message is one of the following:
- Are you the BEST
- Free Win32 API source
- Learn SQL 4 Free
- I Love You..
- Wanna be like a stone ?
- Are you a Soccer Fan ?
- Sexy Screensavers 4 U
- Check it out
- Sample Playboy
- Hardcore Screensavers 4 U
- XXX Screensavers 4 U
- We want peace
- Wanna be a HE-MAN
- Visit us
- One Virus Writer's Story
- One Hacker's Love
- World Tour
- Whats up
- Wanna be my sweetheart ??
- Screensavers from Club Jenna
- Jenna 4 U
- Free rAVs Screensavers
- Feel the fragrance of Love
- Wanna Hack ??
- Sample KOF 2002
- The King of KOF
- Wanna Brawl ??
- Wanna Rumble ??
- Play KOF 2002 4 Free
- Demo KOF 2002
- Free Demo Game
- Wanna be friends ?
- Need money ??
- Are you beautiful
- Who is your Valentine
- Free Screenavers of Love
- Free XXX
- Free Screensavers
- WWE Screensavers
- Freak Out
- Wanna be friends ?
- Things to note
- Lovers Corner
- Patch for Elkern.gen
- Patch for Klez.H
- Free Screensavers 4 U
- Project
- Sample Screensavers
- Hi
- Hello
- Check this shit
- hey check it yaar
- Who is ur Best Friend
- make ur friend happy
- True Love
- Looking for Friendship
- Let's Dance and forget pains
- love speaks from the heart
- Say 'I Like You' To ur friend
- Need a friend?
- war Againest Loneliness
- How sweet this Screen saver
- love speaks from the heart
- Shake it baby
- The world of Friendship
- Check ur friends Circle
- Wowwwwwwwwwww check it
- Are you looking for Love
- Learn How To Love
- Find a good friend
- to ur friends
- to ur lovers
- U realy Want this
- The Hotmail Hack
- You are so sweet
- I Love You
- One Hacker's Love
- I am in Love
- Are you in Love
Body of the message is one of the following:
The attachment is an executable of the worm.
Its filename is one of the following:
- The_Best.scr
- Codeproject.scr
- SQL_4_Free.scr
- I_Love_You.scr
- Stone.scr
- Sex.scrSoccer.scr
- Real.scr
- Plus6.scr
- Plus2.scr
- Playboy.scr
- Hardcore4Free.scr
- xxx4Free.scr
- Screensavers.scr
- Peace.scr
- Body_Building.scr
- Services.scr
- VXer_The_LoveStory.scr
- Hacker_The_LoveStory.scr
- World_Tour.scr
- up_life.scr
- Sweetheart.scr
- Sexy_Jenna.scr
- Jenna_Jemson.scr
- zDenka.scr
- Ravs.scr
- Free_Love_Screensavers.scr
- Romeo_Juliet.scr
- Hacker.scr
- KOF_Fighting.exe
- KOF_Sample.exe
- KOF_Demo.exe
- KOF_The_Game.exe
- KOF2002.exe
- King_of_Figthers.exe
- KOF.exe
- My_Sexy_Pic.scr
- MyProfile.scr
- Ways_To_Earn_Money.exe
- Beautifull.scr
- Valentines_Day.scr
- zXXX_BROWSER.exe
- Britney_Sample.scr
- THEROCK.scr
- FreakOut.exe
- MyPic.scr
- Notes.exe
- Cupid.scr
- FixElkern.com
- FixKlez.com
- Romantic.scr
- Project.exe
- Love.scr
The sender address is one of the following:
- kl@aminoprojects.com
- admin@codeproject.com
- free@sql.library.com
- me@me2K.com
- stone@esterplaza.com
- marketing@suppersoccer.com
- free@sexyscreensavers.com
- sales@real.com
- plus@real.com
- sales@playboy.com
- free@hardcorescreensavers.com
- free@xxxscreensavers.com
- kkn@k2k.comscreensavers@nomadic.com
- nics@nomadic.com
- paul@kqscore.com
- btq@263.com
- services@tcsonline.com
- admin@clubjenna.com
- jenna@jennajameson.com
- zdenka@zpornstars.com
- ravs@go2pussy.com
- love@lovescreensavers.com
- DNA_seraph@163.com
- super@21cn.com
- cathy@21cn.com
- admin@kofonline.com
- zhouyuye@citiz.net
- lubing@7135.com
- hamada@seikosangyo.com
- luoairong@21cn.com
- valentinescreensavers@t2k.com
- screensavers@lovers.com
- admin@zpornstars.com
- newsletters@britneyspears.org
- therock@wwe.com
- ericpan@online.com.pk
- samsun@online.sh.cn
- yjworks@online.sh.cn
- cupid@freescreensavers.com
- av_patch@mcafee.com
- av_patch@norton.com
- av_patch@trendmicro.com
- romanticscreensavers@love.com
- caijob@online.sh.cn
- loverscreensavers@love.com
- Klein Anderson
- Codeproject
- SQL Library
- me2K
- Rocking Stone
- Super Soccer
- Sexy Screensavers
- Real Inc.
- Plus 6
- Plus 2
- Playboy Inc.
- Hardcore Screensavers
- XXX Screensavers
- Nomadic Screensavers
- Keanu Stevenson
- Nicolas Schwarzeneggar
- admin@hackersclub.com
- admin@viruswriters.com
- admin@hackers.com
- Paul Owen
- Benting
- Veronica Anderson
- Club Jenna
- Jenna Jameson
- Zdenka Podkapova
- Raveena Pusanova
- Screensavers of Love
- Romeo & Juliet
- Jaucques Antonio Barkinstein
- Cathy Kindergarten
- KOF Online
- Omega Rugal
- Terry Bogard
- Iori Yagami
- Kyo Kusanagi
- Clark Steel
- Ralph Jones
- Jasmine Stevens
- Ross Anderson
- John Vandervochich
- American Beauty
- Valentine Screensavers
- Lovers Screensavers
- zporNstarS
- britneyspears.org
- The Rock
- Noopma
- Susan
- Jonathan
- Cupid
- McAfee Inc.
- Norton Antivirus
- Trend Micro
- Romantic Screensavers
- Jericho
- Love Inc.
Other information
The worm terminates processes with any of the following strings in the name:
- ANTIVIR
- PVIEW
- WEBSCANX
- RMVTRJANSAFEWEB
- ICMON
- CFINET
- CFINET32
- AVP.EXE
- LOCKDOWN2000
- AVP32
- ZONEALARM
- ALERTSVC
- AMON.EXE
- AVPCC.EXE
- AVPM.EXE
- ESAFE.EXE
- PCCIOMON
- PCCMAIN
- POP3TRAP
- WEBTRAP
- AVCONSOL
- AVSYNMGR
- VSHWIN32
- VSSTAT
- NAVAPW32
- NAVW32
- NMAIN
- LUALL
- LUCOMSERVER
- IAMAPP
- ATRACK
- MCAFEE
- FRW.EXE
- IAMSERV.EXE
- NSCHED32
- PCFWALLICON
- SCAN32
- TDS2-98
- TDS2-NT
- VETTRAY
- VSECOMR
- NISSERV
- RESCUE32
- SYMPROXYSVC
- NISUM
- NAVAPSVC
- NAVLU32
- NAVRUNR
- NAVWNT
- PVIEW95
- F-STOPW
- F-PROT95
- PCCWIN98
- IOMON98
- FP-WIN
- NVC95
- NORTON
- _AVP32
- _AVPCC
- NOD32
- NPSSVC
- NRESQ32
- NSCHED32
- NSCHEDNT
- NSPLUGIN
- LOCKDOWNADVANCED
- NAVAPW32
- NAVAPSVC
- NAVLU32
- NAVRUNR
- NAVW32
- _AVPM
- ALERTSVC
- N32SCANW
- VETTRAY
- VET95
- SWEEP95
- VSHWIN32
- PCCWIN98
- F-AGNT95
- ACKWIN32
- REGEDIT
The worm may create the text file:
- %desktop%\aYerHS.txt
The file may contain some of the following (5) texts:
The worm may create copies of itself in the folder:
- %system%
The following filename is used:
- love.scr
- hotmail_hack.exe
- funny.scr
- friendship.scr
- world_of_friendship.scr
- shake.scr
- Love.scr
- Sweet.scr
- Be_Happy.scr
- Friend_Finder.exe
- I_Like_You.scr
- dance.scr
- GC_Messenger.exe
- True_Love.scr
- Friend_Happy.scr
- Best_Friend.scr life.scr
- life.scr
- colour_of_life.scr
- friendship_funny.scr
The worm may set the following Registry entries:
- [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
- "Start Page" = "%variable%"
The %variable% is one of the following strings:
- http://geocities.com/snak33y3s
- http://www.hackersclub.up.to
- http://www.hrvg.tk
- http://www.ankitfadia.com
- http://www.hackers.com/html/neohaven.html
- http://www.coderz.net
- http://www.blacksun.box.sk
- http://www.neworder.box.sk
- http://www.hirosh.tk
- http://www.unixhideout.com
The worm may attempt to perform a DoS attack on the following server(s):
- infopak.gov.pk
The worm may display the following message:
- Happy Birthday Dear