Find a Partner
This window is encrypted for your security.
Need help? Ask the community or hire an expert.
Go to Avira Answers
W32/Valscr.A-mm, W32/Yaha.eml, I-Worm.Lentin.a, W32/Yaha@MM, W95/Lentin.A@mm, W32.Yaha.F@mm
20,992 Bytes (UPX packed)
Sent by email.
The email sent by the worm:
Subject: Fw: Melt the Heart of your Valentine with this beautiful Screen saver
Check this screen saver
Happy Valentines day
Worm/Lentin.A it infects the local computer right after activated.
It changes the registry entry:
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET ACCOUNT_ MANAGER\ACCOUNTS\00000001 The worm is copied into the hidden files:
Then, the worm changes the registry:
HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" = "c:\recycled\msmdm.exe" %1 %*
The worm is activated every time an .exe file is opened.
The worm searches for email addresses in the Internet files of the current user. It writes some of the addresses into
Description inserted by Crony Walker on Tuesday, June 15, 2004