W32/Yaha.E-mm is No Laughing Matter

執筆者
Jay Munro
Jay Munro
Published: Jan 13, 2004
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

W32/Yaha.E-mm is No Laughing Matter

So far, 2004 is progressing with no surprises or major security problems. Of course were not even halfway through January, so dont get too comfortable. The destructive W32/Nachi/Welchia worm is supposed to be removing itself with the New Year, but may still be living in machines that have not been restarted since last year. McAfee has reduced their threat rating because of its self-removal capability.

A new worm, W32/Bugbros-mm, is getting some notice. Rated as a medium threat by Trend Micro and Symantec, it has the potential for wide distribution. Known also as BugGear, the mass mailing worm comes disguised as an e-mail message from Support@microsoft.com with an attachment of varying file names. The attachment, when run, pops up an error message box saying “Run-time error 76; file not found”. It also sends a copy of itself out to everyone on your Outlook contact list. Like most worms, it relies on a user opening the attachment. Since it appears to come from Microsoft, users should be aware that Microsoft never sends out e-mail messages with attachments. For more info on how to recognize a genuine Microsoft e-mail message, the company has posted this article.

W32/Yaha.E-mm, also known as Lentin, is a destructive mass mailing worm that has been on and off of the MessageLabs top ten e-mail virus since early December. This medium level threat comes in a dozen variations, which can terminate antivirus and security software, reset your Internet Explorer homepage, and launch DOS attacks against certain sites. Of course, it also mines your hard disk for e-mail addresses to send copies of itself. We look at W32/Yaha in our Top Threat this week to see how you stop and remove it.

Our old Phishing virus, Mimail is back making trouble with new variations. Mimail.N, has been reported by Sophos and Panda antivirus, and McAfee, Symantec and Trend antivirus companies have reported Mimail.P. These new Mimail strains share similar hooks to get the user to open the attachment, the only way to get infected. The message offers a “GREAT NEW YEAR OFFER FROM PAYPAL.COM!”, and when the user opens the attachment, they get a form asking for financial and personal information. Like past Mimail variations, these all run as single processes, which can be terminated easily and deleted. Both Mimail variations are not very widely spread yet, so updating your antivirus programs will keep it at bay.

Jay Munro

Jay Munro

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。