Content

W32/YahLover.worm

Type
Virus
SubType
Worm
Discovery Date
09/05/2006
Length
Varies
Minimum DAT
4845 (09/05/2006)
Updated DAT
5810 (11/22/2009)
Minimum Engine
5.1.00
Description Added
09/18/2006
Description Modified
07/16/2008 7:20 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

Update December 7, 2007

McAfee Avert Labs has found a false detection with W32/Yahlover.worm and will be releasing the 5181 DAT Files to correct this issue.  The false detection is being seen on certain AutoIT 3.2.2.0 compiled executables.


The worm changes the custom "away" message in yahoo messenger to point to its download location.

Files Added

  • %WINDIR%\taskmng.exe 

Later variants may also add the following file:

  • %SYSDIR%\Autorun.ini

Registry

The following registry keys are created:

  • hkey_local_machine\software\microsoft\windows\currentversion\run
    \task manager="%WINDIR%\taskmng.exe"
  • hkey_current_user\software\microsoft\windows\currentversion\policies\system\disableregistrytools="1"
  • hkey_current_user\software\microsoft\windows\currentversion\policies\system\disabletaskmgr="1"
  • hkey_current_user\software\yahoo\pager\view\ymsgr_launchcast\content url=http[dot]//chendang.net[blocked]
  • hkey_current_user\software\yahoo\pager\view\ymsgr_buzz\content
    url=http[dot]//chendang.net[blocked]
  • hkey_current_user\software\microsoft\internet explorer\main\start
    page=http[dot]//chendang.net[blocked]
  • hkey_current_user\software\microsoft\internet explorer\main
    \window title="[Random]"

The URLs pointed by the registry vary with diferrent variants, some of the URLs are

  • http[dot]//VuiVeVN.HP[blocked]
  • http[dot]//minhnhut.[blocked]

 

Symptoms

  • Presence of aforementioned registry keys and files.
  • A message window (like the one below) automatically appears at frequent interval of times containing the download link.

 

Method of Infection

The worm spreads through passing malicious link to all user names listed in yahoo buddy list.  Later variants may also spread by Autorun.ini files created on removable drives, so that it may be automatically executed on systems where Autorun is enabled. 

Removal

All Users:
Use specified engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This worm spreads by using Yahoo messenger.  Later variants may also spread by Autorun.ini files created on removable drives, so that it may be automatically executed on systems where Autorun is enabled. 

It sends out download links to all the members in the Yahoo buddy list. Once the link is clicked it uses VB script to download and execute the worm on victim's machine. The VB script is proactively detected as VBS/Psyme with current DATs. Variants of this worm are detected in DATs proactively since DATs 4845 as Generic Startpage.r.

Aliases

  • W32/YahLover.worm.a
  • W32/YahLover.worm.gen

Characteristics

Characteristics -

Update December 7, 2007

McAfee Avert Labs has found a false detection with W32/Yahlover.worm and will be releasing the 5181 DAT Files to correct this issue.  The false detection is being seen on certain AutoIT 3.2.2.0 compiled executables.


The worm changes the custom "away" message in yahoo messenger to point to its download location.

Files Added

  • %WINDIR%\taskmng.exe 

Later variants may also add the following file:

  • %SYSDIR%\Autorun.ini

Registry

The following registry keys are created:

  • hkey_local_machine\software\microsoft\windows\currentversion\run
    \task manager="%WINDIR%\taskmng.exe"
  • hkey_current_user\software\microsoft\windows\currentversion\policies\system\disableregistrytools="1"
  • hkey_current_user\software\microsoft\windows\currentversion\policies\system\disabletaskmgr="1"
  • hkey_current_user\software\yahoo\pager\view\ymsgr_launchcast\content url=http[dot]//chendang.net[blocked]
  • hkey_current_user\software\yahoo\pager\view\ymsgr_buzz\content
    url=http[dot]//chendang.net[blocked]
  • hkey_current_user\software\microsoft\internet explorer\main\start
    page=http[dot]//chendang.net[blocked]
  • hkey_current_user\software\microsoft\internet explorer\main
    \window title="[Random]"

The URLs pointed by the registry vary with diferrent variants, some of the URLs are

  • http[dot]//VuiVeVN.HP[blocked]
  • http[dot]//minhnhut.[blocked]

 

Symptoms

Symptoms -

  • Presence of aforementioned registry keys and files.
  • A message window (like the one below) automatically appears at frequent interval of times containing the download link.

 

Method of Infection

Method of Infection -

The worm spreads through passing malicious link to all user names listed in yahoo buddy list.  Later variants may also spread by Autorun.ini files created on removable drives, so that it may be automatically executed on systems where Autorun is enabled. 

Removal -

Removal -

All Users:
Use specified engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A