W32.Yaha.K@mm
Norton has a listing up on it and tools to remove it too
url;
http://www.sarc.com/avcenter/venc/da...yaha.k@mm.html
W32.Yaha.K@mm
Discovered on: December 24, 2002
Last Updated on: January 02, 2003 04:46:32 PM
Due to an increase in submissions, Symantec Security Response has upgraded this threat from a Category 2 to a Category 3 as of December 30, 2002.
W32.Yaha.K@mm is a worm that is a variant of W32.Yaha.J@mm. This worm terminates some antivirus and firewall processes. It uses its own SMTP engine to email itself to all the contacts in the Windows Address Book, MSN Messenger, .NET Messenger, Yahoo Pager, and all the files whose extensions contain the letters HT. The email message has randomly chosen the subject line, message, and attachment name.
This threat is written in the Microsoft C++ language and is compressed with UPX. The uncompressed size is about 75 KB.
Removal tool
Symantec has provided a tool to remove infections of W32.Yaha.K@mm.
click-here to obtain the tool. This is the easiest way to remove this threat and should be tried first.
Also Known As: W32/Yaha.k [McAfee], I-Worm.Lentin.i [KAV], Win32/Yaha.K@mm [GeCAD], W32/Yaha-K [Sophos], Win32.Yaha.K [CA], W32/Yaha.M-mm [MessageLabs]
Type: Worm
Infection Length: 34,304 bytes
Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me
Systems Not Affected: Macintosh, OS/2, UNIX, Linux