Domovoy,
WORM_YAHA.F
Virus type: Worm
Destructive: No
Aliases: LENTIN.F, YAHA.F, I-Worm.Lentif.f
Pattern file needed: 306
Scan engine needed: 5.200
Overall risk rating: Low
--------------------------------------------------------------------------------
Reported infections: Low
Damage Potential: High
Distribution Potential: High
--------------------------------------------------------------------------------
Description:
This worm arrives in an email message and is disguised as a screensaver program. It has a built-in SMTP engine, which it uses to spam itself to other users. It accesses different sources for its spam recipients.
The email it sends out is HTML-formatted and can be either of the following:
Subject: Melt the Heart of your Valentine with this beautiful Screen saver
Message Body:
<<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>>
This e-mail is never sent unsolicited. If you need to unsubscribe, follow the instructions at the bottom of the message.
**************************************************
Melt the Heart of your loved ones with these beautiful Screen saver from http://www.screensaverin.com
* To remove yourself from this mailing list, point your browser to:
http://screensaverin.com/remove?freescreensaver
* Enter your email address (%EmailAddress%) in the field provided and click "Unsubscribe".
OR...
* Reply to this message with the word "remove" in the subjt line.
This message was sent to address %EmailAddress%
X-PMG-Recipient:
<<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>>
Attachment: VALENTIN.SCR
Subject: Fw: Melt the Heart of your Valentine with this beautiful Screen saver
Message Body: Hi
Check this screen saver
Happy Valentines day
See u
----- Original Message -----
From: "Screen Saver"
To:
Sent: Friday, February 11, 2002 8:38 PM
Subject: Melt the Heart of your Valentine with this beautiful Screen saver
<<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>>
This e-mail is never sent unsolicited. If you need to unsubscribe, follow the instructions at the bottom of the message.
**************************************************
Melt the Heart of your loved ones with these beautiful Screen saver from http://www.screensaverin.com
* To remove yourself from this mailing list, point your browser to:
http://screensaverin.com/remove?freescreensaver
* Enter your email address (%EmailAddress%) in the field provided and click "Unsubscribe".
OR...
* Reply to this message with the word "remove" in the subjt line.
This message was sent to address %EmailAddress%
X-PMG-Recipient: <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>>
Attachment: VALENTIN.SCR
Solution (лечение):
Click Start>Run.
In the Open: input box, type:
command /c copy %WinDir%\regedit.exe regedit.com | regedit.com
*where %WinDir% is the Windows directory, usually C:\Windows or C:\Winnt.
Hit the Enter key.
Open Registry Editor. Click Start>Run, type REGEDIT.COM then hit the Enter key.
In the left panel, double click the following:
HKEY_CLASSES_ROOT>exefile>shell>open>command
In the right panel, locate the registry entry, Default, and check whether its value is the path and filename of the malware file.
If the value is the file, right-click Default and select Modify to change its value.
In the Value data: input box, delete the existing value and type the default value:
"%1" %*
Close Registry Editor.
Click Start>Run.
In the Open: input box, type:
command /c del %WinDir%\regedit.com
Hit the Enter key.
Scan your system with Trend Micro antivirus and delete all files detected as WORM_YAHA.F. To do this Trend Micro customers must download the latest pattern file and scan their system. Other email users may use HouseCall, Trend Micro's free online virus scanner.
------------------------------------------------------------------------------------
Ссылка на оригинал: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_YAHA.F
------------------------------------------------------------------------------------
Вот, вроде и все... И описание, и лечение... Пользуйся!