Search Solo Products, Services and others Overview of the Site Design and Build a Career Contact us for customer service and other feedback info SRN Micro Privacy Statement

 


EXELOADER.EXE PROCESS INFORMATION

Process Name  : Exeloader.exe

Process Path : %System%\ExeLoader.exe" [ C:\Windows\System32\ExeLoader.exe ]

Process type    : Internet Worm

Malware Name : W32.Yaha.P@mm

Alias             : I-Worm.Lentin.m, I-Worm/Yaha.P,  W32/Yaha-P, WORM_YAHA.P

Threat level : Low

Process Details :

                     ExeLoader.exe is dropped by Yaha.P worm when the infected mail attachment is executed. It is a mass mailing worm uses e-mail addresses stored in Windows Address book and also collects addresses from .ht* files to distribute infected messages. It also spreads through MSN messenger list, ICQ list and Yahoo pager list.

                     Yaha.P arrives as an e-mail attachment with random message subject and message body. The SMTP server used to send the emails is chosen either from the registry or from the following list inside the worm body.

The worm uses the following combination of words as subject.

searching for true Love
you care ur friend
Who is ur Best Friend
make ur friend happy
True Love
Dont wait for long time
Free Screen saver
Friendship Screen saver
Looking for Friendship
Need a friend?
Find a good friend
Best Friends
I am For u
Life for enjoyment
Nothink to worryy
Ur My Best Friend
Say 'I Like You' To ur friend
Easy Way to revel ur love
Wowwwwwwwwwww check it
Send This to everybody u like
Enjoy Romantic life
Let's Dance and forget pains
war Againest Loneliness
How sweet this Screen saver
Let's Laugh
One Way to Love
Learn How To Love
Are you looking for Love
love speaks from the heart
Enjoy friendship
Shake it baby
Shake ur friends
One Hackers Love
Origin of Friendship
The world of lovers
The world of Friendship
Check ur friends Circle
Friendship
how are you
U r the person?
Hi
U realy Want this
Romantic
humour
New
Wonderfool
excite
Cool
charming
Idiot
Nice
Bullshit
One
Funny
Great
LoveGangs
Shaking
powful
Joke
Interesting
Interesting
Screensaver
Friendship
Love
relations
stuff
to ur friends
to ur lovers
for you
to see
to check
to watch
to enjoy
to share

The message body will be one of the following:

"Hi dear
check the attach
see u"

"Hi
Check the Attachment ..
See u"

"Attached one Gift for u.."

"wOW CHECK THIS"

"Check the attachment"

"See the attachement"

"Enjoy the attachement"

or

"More details attached"

The remainder of the message may contain the following text resembling a
forwarded email. The From and Subject fields of the forwarded message are
also variable but the message will always contain the text:

"This e-mail is never sent unsolicited. If you need to unsubscribe,
follow the instructions at the bottom of the message.
***********************************************************

Enjoy this friendship Screen Saver and Check ur friends circle...

Send this screensaver from <web address> to everyone you
consider a FRIEND, even if it means sending it back to the person
who sent it to you. If it comes back to you, then you'll know you
have a circle of friends.

* To remove yourself from this mailing list, point your browser to:
<web address>
* Enter your email address (<sender's address>) in the field provided
and click "Unsubscribe".

OR...

* Reply to this message with the word "REMOVE" in the subject line.

This message was sent to address <sender's address>
X-PMG-Recipient: <sender's address>
<<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>> <<<>>>"

The attachment filename name will be one of the following. The attachment name will contain two extenstions.

screensaver
screensaver4u
screensaver4u
screensaverforu
freescreensaver
love
lovers
lovescr
loverscreensaver
loversgang
loveshore
love4u
lovers
enjoylove
sharelove
shareit
checkfriends
urfriend
friendscircle
friendship
friends
friendscr
friends
friends4u
friendship4u
friendshipbird
friendshipforu
friendsworld
werfriends
passion
bullshitscr
shakeit
shakescr
shakinglove
shakingfriendship
passionup
rishtha
greetings
lovegreetings
friendsgreetings
friendsearch
lovefinder
truefriends
truelovers
fucker
loveletter
resume
biodata
dailyreport
mountan
goldfish
weeklyreport
report
love

                     The first extension is chosen from doc, mp3, xls, wav, txt, jpg, gif, dat, bmp, htm, mpg, mdb, zip. The second extension is chosen from pif, bat, scr.

                     When the infected e-mail attachment is executed, it copies itself to Windows System folder as exeLoader .exe, mstask32.exe. After that it modifies the registry to load automatically whenever an "EXE" file is executed. The registry key modified will be

HKEY_CLASSES_ROOT\exefile\shell\open\command

                     In some cases it uses IFRAME vulnerability to infect. When the user views the e-mail the embedded code is executed automatically and it drops the virus. Microsoft released security patches to close this security hole. If you haven't installed, you can get a copy at http://www.microsoft.com/windows/ie/download/critical/Q290108/default.asp

                     When active in memory it will disable antivirus programs. Yaha worm has the ability to spread through network. Yaha.P worm doesn't contain any destructive payload. It performs a denial of service (DoS) attack on a particular Pakistani domain. If you have deleted the worm file before fixing the registry entries your applications will NOT work. In that case manual registry modifcation will be required. Instead of deleting the worm file manually, you can use Solo trial version to remove Yaha.P worm safely.

How can I protect my system?

                   Solo has incorporated ExeLoader.exe in its signature file to protect users from this worm attack. Solo antivirus registered users are already protected from this worm. Make sure that you have installed registered version of Solo Antivirus to protect your system from all virus threats.

How to remove this worm?

                   If you are already infected with ExeLoader.exe, you can remove it from your computer using Solo Antivirus software. Solo antivirus can detect and remove W32.Yaha.P@mm safely. Use the following link to Download 30 day trial version of Solo antivirus to remove viruses from your computer.

                   Solo anti-virus not only scans for all viruses, it contains a unique System Integrity Checker to protect you from New Internet Worms, Backdoors and malicious VB, Java Scripts. It also effectively removes all existing Internet Worms, File viruses, malicious VBS, Java scripts, Trojans, Backdoors, boot sector, partition table and macro viruses.

You can purchase Solo antivirus using the link