Worm_yahlover.az


 
Thread Tools Search this Thread
Special Forums Cybersecurity Malware Advisories (RSS) Worm_yahlover.az
# 1  
Old 07-17-2008
Worm_yahlover.az

This worm may be downloaded unknowingly by a user when visiting malicious Web sites.

This worm drops copies of itself. It also drops component files which Trend Micro detects as MAL_OTORUN2.

This worm creates registry entries to enable its automatic execution at every system startup. It also uses Windows Task Scheduler to create a scheduled task that it uses to executes a dropped copy.

This worm sends messages to target recipients using instant messaging applications. This worm drops copies of itself in all removable drives. It drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.

This worm accesses Web sites to download files which Trend Micro detects as the following malware:

  • WORM_YAHLOVER.BH
  • TROJ_AGENT.ADZE
  • BKDR_POISON.DS
This worm terminates a certain process, if found running in memory.



More...
Login or Register to Ask a Question

Previous Thread | Next Thread
Login or Register to Ask a Question
GENWORM(1)						      General Commands Manual							GENWORM(1)

NAME
genworm - generate a RADIANCE description of a functional worm SYNOPSIS
genworm mat name 'x(t)' 'y(t)' 'z(t)' 'r(t)' nseg [ -e expr ][ -f file ] DESCRIPTION
Genworm produces a RADIANCE scene description of a worm defined by the parametric equations x(t), y(t), z(t), and r(t) (the radius). T will vary from 0 to 1 in steps of 1/nseg. The surface will be composed of nseg cones or cylinders and nseg+1 spheres. The expressions are of the same type used in RADIANCE function files. Auxiliary expressions and/or files may be specified in any number of -e and -f options. EXAMPLE
To generate a banana: genworm yellow banana '0' '5*sin(t)' '5*cos(t)' '.4-(.5-t)*(.5-t)' 20 AUTHOR
Greg Ward BUGS
Since the worm is constructed of intersecting surfaces, only opaque materials should be used with this object. Also, a worm cannot double back inside itself without making a mess. SEE ALSO
genrbox(1), genrev(1), gensurf(1), icalc(1), rpict(1), rvu(1), xform(1) RADIANCE
11/15/93 GENWORM(1)