PDA

View Full Version : Warning!!! JS/Yamanner - New Graphic Site


pykko
June 13th, 2006, 12:09 PM
Hello!
I've read about this worm: JS/Yamanner recently and it's currently spreading here in Romania. :(

I've seen in version 1.1595 that NOD32 added JS/Yamaihoo.A. Is this the same one?

Here's a description of the worm: http://www.avira.com/en/threats/section/fulldetails/id_vir/2128/js_yamanner.html

It comes in an e-mail from %collected email addresses%@yahoo.com
%collected email addresses%@yahoogroups.com

with the following subject: New Graphic Site

One of my friends actually received it and clicked on it and the e-mail was sent to almost evryone in his address book. He uses NOD32 but he saw no warning. :-\

proactivelover
June 13th, 2006, 12:20 PM
i think nod32 detect it as JS/Yamaihoo.A

pykko
June 13th, 2006, 12:52 PM
yes, as I've stated. ;D

pykko
June 13th, 2006, 03:54 PM
I"ve received the mail myself now. :(

I don't know what to say? Is it detected or not? Can I forward the mail to ESET...but for this I should open it. ;D
Hope an ESET Mod will answer to this thread....

ASpace
June 13th, 2006, 04:26 PM
{QUOTE-> I"ve received the mail myself now. :(

I don't know what to say? Is it detected or not? Can I forward the mail to ESET...but for this I should open it. ;D
Hope an ESET Mod will answer to this thread.... <-QUOTE}


If detection was added (obviously it was) then NOD32 should detect it even if it is a new variant . Let's not forget about the advanced heuristics .

However I suggest you not to take the risk if this is on a productive machine . ESET would be grateful to receive a sample , in my opinion :)

pykko
June 13th, 2006, 04:38 PM
well, I'm a risky boy so I've opened the e-mail because it was sent to me at request. ;D One of my friends opened it and NOD32 did not prompt. So he forwarded the e-mail to me and I've opened it.
Besides I've read that yahoo made an update to protect its users against this threat. ;)
Not even Avira said a word about it. And Avira has the definition as you may notice from my first post. :)

ASpace
June 13th, 2006, 04:40 PM
{QUOTE-> well, I'm a risky boy so I've opened the e-mail because it was sent to me at request. ;D One of my friends opened it and NOD32 did not prompt. So he forwarded the e-mail to me and I've opened it.
Besides I've read that yahoo made an update to protect its users against this threat. ;)
Not even Avira said a word about it. And Avira has the definition as you may notice from my first post. :) <-QUOTE}

So does now NOD detect it on your computer , latest version and updates ?! :blink:

ASpace
June 13th, 2006, 04:42 PM
You can test your NOD32 using this
http://www.eset.com/eicar.com


;D

pykko
June 13th, 2006, 04:46 PM
NOD32 and Avira foound nothing while opening that e-mail, not even after scanning my computer. ;)
Perhaps it's malign only. :)

ASpace
June 13th, 2006, 04:49 PM
{QUOTE-> NOD32 and Avira foound nothing while opening that e-mail, not even after scanning my computer. ;)
Perhaps it's malign only. :) <-QUOTE}


Send the files to ESET , either by the quarantine or to samples@eset.com

May be this is a new variant or something like that :)

pykko
June 13th, 2006, 04:54 PM
I could only send them the mail. ???

i_kenefick
June 13th, 2006, 05:11 PM
{QUOTE-> I could only send them the mail. ??? <-QUOTE}

this is enough. They already should have a sample through the sample sharing network between AV companies.

ASpace
June 13th, 2006, 05:13 PM
{QUOTE-> this is enough. They already should have a sample through the sample sharing network between AV companies. <-QUOTE}



It is really strange , by the way , that this isn't detected ???

i_kenefick
June 13th, 2006, 06:23 PM
{QUOTE-> It is really strange , by the way , that this isn't detected ??? <-QUOTE}

Hmm - It's not widely spread. It's in the news because it's zero day exploit. By default users are directed to the new beta version of yahoo mail which is not vulnerable. I think the amount of infections is very small. How do you know ESET dont already detect this?

pykko
June 14th, 2006, 03:56 AM
well, we shall see when Marcos is here. ;)

ASpace
June 14th, 2006, 09:33 AM
{QUOTE-> Hmm - It's not widely spread. It's in the news because it's zero day exploit. By default users are directed to the new beta version of yahoo mail which is not vulnerable. I think the amount of infections is very small. How do you know ESET dont already detect this? <-QUOTE}

This is in their database 1.1595 , I guess

pykko
June 14th, 2006, 09:47 AM
Added a new variant in 1.1598 also. ;)
I've found the e-mail didn't contain all the executable code for the malware so it was no danger. :)

ASpace
June 14th, 2006, 10:25 AM
Just wanted to add this and I saw your post ,pykko . Oh , no problem , here is the prove : ;D ;D ;D

NOD32