Content
W32/YahLover.worm
- Type
- Virus
- SubType
- Worm
- Discovery Date
- 09/05/2006
- Length
- Varies
- Minimum DAT
- 4845 (09/05/2006)
- Updated DAT
- 5810 (11/22/2009)
- Minimum Engine
- 5.1.00
- Description Added
- 09/18/2006
- Description Modified
- 07/16/2008 7:20 PM (PT)
Tab Navigation
Characteristics
Update December 7, 2007
McAfee Avert Labs has found a false detection with W32/Yahlover.worm and will be releasing the 5181 DAT Files to correct this issue. The false detection is being seen on certain AutoIT 3.2.2.0 compiled executables.
The worm changes the custom "away" message in yahoo messenger to point to its download location.

Files Added
- %WINDIR%\taskmng.exe
Later variants may also add the following file:
- %SYSDIR%\Autorun.ini
Registry
The following registry keys are created:
- hkey_local_machine\software\microsoft\windows\currentversion\run
\task manager="%WINDIR%\taskmng.exe" - hkey_current_user\software\microsoft\windows\currentversion\policies\system\disableregistrytools="1"
- hkey_current_user\software\microsoft\windows\currentversion\policies\system\disabletaskmgr="1"
- hkey_current_user\software\yahoo\pager\view\ymsgr_launchcast\content url=http[dot]//chendang.net[blocked]
- hkey_current_user\software\yahoo\pager\view\ymsgr_buzz\content
url=http[dot]//chendang.net[blocked] - hkey_current_user\software\microsoft\internet explorer\main\start
page=http[dot]//chendang.net[blocked] - hkey_current_user\software\microsoft\internet explorer\main
\window title="[Random]"
The URLs pointed by the registry vary with diferrent variants, some of the URLs are
- http[dot]//VuiVeVN.HP[blocked]
- http[dot]//minhnhut.[blocked]
Symptoms
- Presence of aforementioned registry keys and files.
- A message window (like the one below) automatically appears at frequent interval of times containing the download link.

Method of Infection
The worm spreads through passing malicious link to all user names listed in yahoo buddy list. Later variants may also spread by Autorun.ini files created on removable drives, so that it may be automatically executed on systems where Autorun is enabled.
Removal
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
This worm spreads by using Yahoo messenger. Later variants may also spread by Autorun.ini files created on removable drives, so that it may be automatically executed on systems where Autorun is enabled.
It sends out download links to all the members in the Yahoo buddy list. Once the link is clicked it uses VB script to download and execute the worm on victim's machine. The VB script is proactively detected as VBS/Psyme with current DATs. Variants of this worm are detected in DATs proactively since DATs 4845 as Generic Startpage.r.
Aliases
- W32/YahLover.worm.a
- W32/YahLover.worm.gen
Characteristics
Characteristics -
Update December 7, 2007
McAfee Avert Labs has found a false detection with W32/Yahlover.worm and will be releasing the 5181 DAT Files to correct this issue. The false detection is being seen on certain AutoIT 3.2.2.0 compiled executables.
The worm changes the custom "away" message in yahoo messenger to point to its download location.

Files Added
- %WINDIR%\taskmng.exe
Later variants may also add the following file:
- %SYSDIR%\Autorun.ini
Registry
The following registry keys are created:
- hkey_local_machine\software\microsoft\windows\currentversion\run
\task manager="%WINDIR%\taskmng.exe" - hkey_current_user\software\microsoft\windows\currentversion\policies\system\disableregistrytools="1"
- hkey_current_user\software\microsoft\windows\currentversion\policies\system\disabletaskmgr="1"
- hkey_current_user\software\yahoo\pager\view\ymsgr_launchcast\content url=http[dot]//chendang.net[blocked]
- hkey_current_user\software\yahoo\pager\view\ymsgr_buzz\content
url=http[dot]//chendang.net[blocked] - hkey_current_user\software\microsoft\internet explorer\main\start
page=http[dot]//chendang.net[blocked] - hkey_current_user\software\microsoft\internet explorer\main
\window title="[Random]"
The URLs pointed by the registry vary with diferrent variants, some of the URLs are
- http[dot]//VuiVeVN.HP[blocked]
- http[dot]//minhnhut.[blocked]
Symptoms
Symptoms -
- Presence of aforementioned registry keys and files.
- A message window (like the one below) automatically appears at frequent interval of times containing the download link.

Method of Infection
Method of Infection -
The worm spreads through passing malicious link to all user names listed in yahoo buddy list. Later variants may also spread by Autorun.ini files created on removable drives, so that it may be automatically executed on systems where Autorun is enabled.
Removal -
Removal -
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A