W32.Yaha.T@mm:
Is a worm that is a variant of W32.Yaha.J@mm.
Terminates some antivirus and firewall processes.
Uses its own SMTP engine to email itself to all the contacts in the Windows Address Book, MSN Messenger, .NET Messenger, Yahoo Pager, and in all the files whose extensions contain the letters HT.
The email message has a randomly chosen subject line, message, and attachment name. The attachment will have a .com, .exe, or .scr file extension.
This threat is written in the Microsoft C++ language and is compressed with FSG.
Also Known As: I-Worm.Lentis.gen [KAV], W32/Yaha.t@MM [McAfee], W32/Yaha-T [Sophos]
Type: Worm
Infection Length: 51,424 bytes
Systems Affected: Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Me
Systems Not Affected: Macintosh, OS/2, UNIX, Linux