Need help? Ask the community or hire an expert.
Go to Avira Answers
Alias:W32/Valscr.A-mm, W32/Yaha.eml, I-Worm.Lentin.a, W32/Yaha@MM, W95/Lentin.A@mm, W32.Yaha.F@mm
Type:Worm 
Size:20,992 Bytes (UPX packed) 
Origin: 
Date:00-00-0000 
Damage:Sent by email. 
VDF Version:6.23.00.00 
Danger:Medium 
Distribution:Low 

DistributionThe email sent by the worm:

Subject: Fw: Melt the Heart of your Valentine with this beautiful Screen saver

Body:
Hi
Check this screen saver
Happy Valentines day
See u
administrator

Attachment: valentin.scr

Technical DetailsWorm/Lentin.A it infects the local computer right after activated.
It changes the registry entry:
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET ACCOUNT_ MANAGER\ACCOUNTS\00000001 The worm is copied into the hidden files:
C:\RECYCLED\MSSCRA.EXE
C:\RECYCLED\MSMDM.EXE.

Then, the worm changes the registry:
HKEY_CLASSES_ROOT\exefile\shell\open\command "(Default)" = "c:\recycled\msmdm.exe" %1 %*
The worm is activated every time an .exe file is opened.

The worm searches for email addresses in the Internet files of the current user. It writes some of the addresses into %WINDIR%\SCREEND.DLL.
Description inserted by Crony Walker on Tuesday, June 15, 2004

Back . . . .