ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security management Toolkit

Yarner worm could delete your Windows files

Robert Vamosi CNet

Published: 19 Feb 2002 18:34 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A dangerous worm from Germany is loose on the Internet. Yarner (w32.yarner.a@mm) appears to be a newsletter about Trojan horses from a legitimate security site but is actually a dangerous worm. Yarner is a Windows PE EXE file about 434K in size, written in Delphi. It uses its own email engine to send copies of itself to others. Once executed, the worm deletes the Windows directory on infected computers. At present, the infections are limited to Germany, however, a new variation could be produced in English or any other language. Because of the dangerous potential of this worm, Yarner ranks a 7/10 on the ZDNet Virus Meter.

How it works
Yarner arrives by email and appears to be from Trojaner-Info [webmaster@trojaner-info.de]. This is a real address and is not the true origin of this email. The subject of the infected email reads "Trojaner-Info Newsletter [Current Date]" The body text is in German and appears to be a newsletter which translates into English as:

"Hello!
Welcome to the latest newsletter from Trojaner-Info.de
Content:
1. YAW 2.0 - the latest version of our porn-dialer warner
****
1. YAW 2.0 - Our porn-dialer warner in its latest version.
Our widely used Dialerwarner YAW is now available in a brand new and enhanced version. All subscribers to our newsletter get this version for free with this newsletter.
Just start the attached file and YAW 2.0 installs itself.
If there are any questions the programmer of this unique tool is available at [...]
Have fun with YAW!
http://www.trojaner-info.de/dialer/yaw.shtml
****
That's it with the latest Trojaner-Info news, thank you for your attention and we wish all our readers a pleasant week."

The attached file with this email is yawsetup.exe

If executed, Yarner will copy itself to the Windows directory as notedpad.exe, overwriting the system's original Notepad application (notepad.exe). Whenever you launch Notepad, Yarner uses notedpad.exe to hide its presence. The worm adds two additional files: kerneI32.daa (which the worm uses to write emails) and kerneI32.das (which the worm uses to write known SMTP).

The worm then changes this registry file:

HKCU\Software\Microsoft\Windows\CurrentVersion\Runonce [random characters] = [random characters].exe

There can be up to 100 random characters assigned to these values.

To send email, Yarner gains access to the Microsoft Outlook address book then scans all .php, .htm, .shtm, .cgi, .pl files in all subdirectories, looking for additional email addresses. Yarner then uses its own SMTP engine (email program) to send emails and connects to its own list of servers, including:

216.113.14.106
joy-go.gr.jp
ctripserver.ctrip.com.cn
202.101.62.207
cocess.cocess.co.kr
mail.bizpoint.com.sg
ns2.webshock.co.kr
olympus.mda.com.tr
linux2.ele-china.com
mailsvr.hanace.co.kr

After it has sent copies of itself, Yarner then deletes all files in the Windows directory.

Prevention
Users of Microsoft Outlook 2002 and users of Outlook 2000 who have installed the Security Update should be safe from opening the attached file with Yarner. Users who have not upgraded to Outlook 2002 or who have not installed the Security Update for Outlook 2000 should do so. In general, do not open attached files in email without first saving them to hard disk and scanning them with updated antivirus software. Contact your antivirus vendor to obtain the most current antivirus signature files that include Yarner.

Removal
Almost all the antivirus software companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see Central Command, F-Secure, Kaspersky, McAfee, Norman, Sophos, Symantec, and Trend Micro.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
12 out of 18 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

5 comments

Featured Talkback

It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link

DOWNLOAD

Security Essentials

Security Downloads

There are masses of security suites out there for small businesses. Here's a selection to get you started

Editor’s Rating
1 Norton 360™
2 AVG Anti-Virus Free Edition Rating: 10
3 PC Tools AntiVirus Free Edition
4 Kaspersky Internet Security

See All Software

In association with Symantec