Yaha


Name: Yaha
Aliases: W32.Yaha@mm, W32.Valscr.A-mm, Lentin, I-Worm.Lentin,
Ports:
Files: Valentin.scr - 20,992 bytes Msscra.exe - Msmdm.exe - Www.dll - ??? bytes Screenback.dll - ??? bytes Screen.dll - ??? bytes *.exe - 23,320 bytes (version B) - 25,619 bytes (version D) - 25,619 bytes (version E) - 29,948 bytes (version F)
Created:
Requires:
Actions: Worm / Mail trojan / SMTP server / MSN trojan
Registers: HKEY_LOCAL_MACHINE\Software\Classes\exefile\shell\open\commandHKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts\00000001HKEY_LOCAL_MACHINE\Software\Classes\Exefile\shell\open\command c:\recycled\
Notes: Works on Windows 95, 98, ME, NT, 2000 and XP, together with MS MSN Messenger.
Country:
Program:

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>