![]() The limit of $50, your payment will be send to your registration address by With us through your account, we will pay you $1.5.Once your account reaches To your friends using your account ID and for each person who registers With us using the links provided in the software. Product.If you are satified then you can send it to your friends.Īll you have to do is to install the software and register an account You have been chosen to try a free fully functional sample of our The attached product is send as a part of our official campaign In those messages subjects, bodies and attachment names are correlated.Ī subject of an infected email can be one of the following:Īn infected attachment name can be one of the following:Īn infected message body can contain one of the following: The worm composes several different types of emails. Then the worm sends itself to all found email addresses. The worm looks for email addresses in Windows Address Book, cache folders of NET and MSN messengers and in Yahoo Messenger profile folders. One of the threads kills processes with the following names: ![]() The worm creates several threads that refresh its Registry keys and continuously restore worm's files if they are deleted from a hard drive. ![]() Also the worm modifies the default EXE file startup key: The %WinSysDir% represents Windows System directory name. [HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices "WinServices" = "%WinSysDir%\WinServices.exe" "WinServices" = "%WinSysDir%\WinServices.exe" Then the worm creates a startup key for WinServices.exe file in System Registry: When run, the worm installs itself to system by copying its file to Windows System directory 3 times with the following names: ![]() To block the virus, strip attachments ending with. This version, also known as Yaha.M, is a massmailer - like the others.Įmails sent by this version talk about "Enjoy this friendship Screen Saver and Check ur friends circle." etc. Yaha.K is a Windows massmailer, which randomly composes its email subject, body and attachment name.Ī new variant of the Yaha virus family was found on Sunday the 22nd of December, 2002. F-Secure is upgrading the Yaha.K email worm to level 2 because it has been reported from several different countries.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |