Win32:Yaha-E
Win32:Yaha-E is an Internet worm which spreads via email. When the
worm is first run it will imitate a screen saver by repeatedly displaying
the following messages on the screen in various colours:
Two additional files with random name are created in the Windows folder. One has a DLL extension and contains a list of email addresses found on the infected computer. The second file has a TXT extension and contains the text "iNDian sNakes pResents yAha.E". The worm tries to disable security and antivirus software by terminating many processes - it disables for example Zonealarm, AVP, Mcafee, Norton, Fprot, PCcillin and several others. The email sent by the worm is highly variable. The subject line of the email is created using a combination of words and phrases from the following list: "searching for true Love" " you care ur friend" "Who is ur Best Friend" "make ur friend happy" "True Love" "Dont wait for long time" "Free Screen saver" "Friendship Screen saver" "Looking for Friendship" "Need a friend?" "Find a good friend" "Best Friends" "I am For u" "Life for enjoyment" "Nothink to worryy" "Ur My Best Friend" "Say 'I Like You' To ur friend" "Easy Way to revel ur love" "Wowwwwwwwwwww check it" "Send This to everybody u like" "Enjoy Romantic life" "Let's Dance and forget pains" "war Againest Loneliness" "How sweet this Screen saver" "Let's Laugh" "One Way to Love" "Learn How To Love" "Are you looking for Love" "love speaks from the heart" "Enjoy friendship" "Shake it baby" "Shake ur friends" "One Hackers Love" "Origin of Friendship" "The world of lovers" "The world of Friendship" "Check ur friends Circle" "Friendship" "how are you" "U r the person?" "Hi" "U realy Want this" "Romantic" "humour" "New" "Wonderfool" "excite" "Cool" "charming" "Idiot" "Nice" "Bullshit" "One" "Funny" "Great" "LoveGangs" "Shaking" "powful" "Joke" "Interesting" "Interesting" "Screensaver" "Friendship" "Love" "relations" "stuff" "to ur friends" "to ur lovers" "for you" "to see" "to check" "to watch" "to enjoy" "to share" The message text contains:
This e-mail is never sent unsolicited. If you need to unsubscribe,
Enjoy this friendship Screen Saver and Check ur friends circle... Send this screensaver from The attached file has two extensions - the last and important one is
pif,
bat or scr. The filename is could be one of:
The worm uses its own SMTP routine and uses the users SMTP server or one from a list contained within the worm itself. Any avast! with VPS file dated on or after 20th June 2002 is able to detect this worm. Refer: Avast
|