Summary

Summary
Action
More Information
| Included in our products from | February 2003 (3.66) |
|---|---|
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please read the instructions for removing W32/Yaha-J.
More Information
W32/Yaha-J is a worm which spreads via email. The mail sent by the worm has a variable subject line and attached file name. The attached file has an extension of SCR. The message text is:
"<<>> <<>> <<>> <<>> <<>> <<>> <<>> <<>> <<>> <<>>
This e-mail is never sent unsolicited. If you need to unsubscribe, follow the instructions at the bottom of the message.
***********************************************************
Enjoy this friendship Screen Saver and Check ur friends circle...
Send this screensaver from www.truefriends.net to everyone you consider a FRIEND, even if it means sending it back to the person who sent it to you. If it comes back to you, then you'll know you have a circle of friends.
* To remove yourself from this mailing list, point your browser to: http://truefriends.net/remove?freescreensaver
* Enter your email address in the field provided and click "Unsubscribe".
OR...
* Reply to this message with the word "REMOVE" in the subject line.
<<>> <<>> <<>> <<>> <<>> <<>> <<>> <<>> <<>> <<>>"
When first run the worm will display a message box with the title "Error" and the message "Application initialisation error". W32/Yaha-J will then create copies of itself named winreg.exe, msnmsg32.exe and nav32.exe in the Windows system folder.
The worm creates the following registry entries so that winreg.exe is run when Windows is started:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Winreg
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Winreg
The worm will also add the name and path to nav32.exe to the registry entry
HKCR\exefile\shell\open\command.
W32/Yaha-J will also attempt to terminate processes with the following names:
ALERTSVC
AMON.EXE
ANTIVIR
APACHE.EXE
ATRACK
AVCONSOL
AVP.EXE
AVP32
AVPCC.EXE
AVPM.EXE
AVSYNMGR
CFINET
CFINET32
ESAFE.EXE
F-PROT95
FP-WIN
FRW.EXE
F-STOPW
IAMAPP
IAMSERV.EXE
ICMON
IOMON98
LOCKDOWN2000
LOCKDOWNADVANCED
LUALL
LUCOMSERVER
MCAFEE
NAVAPSVC
NAVAPW32
NAVLU32
NAVRUNR
NAVW32
NAVWNT
NISSERV
NISUM
NMAIN
NORTON
NSCHED32
NVC95
PCCIOMON
PCCMAIN
PCCWIN98
PCFWALLICON
POP3TRAP
PVIEW95
RESCUE32
SAFEWEB
SCAN32
SYMPROXYSVC
TDS2-98
TDS2-NT
VETTRAY
VSECOMR
VSHWIN32
VSSTAT
WEBSCANX
WEBTRAP
ZONEALARM
