The false detection is being seen on certain AutoIT 3.2.2.0 compiled executables. McAfee Avert Labs has found a false detection with W32/Yahlover.worm and will be releasing the 5181 DAT Files to correct this issue. Variants of this worm are detected in DATs proactively since DATs 4845 as Generic Startpage.r.Characteristics. Once the link is clicked it uses VB script to download and execute the worm on victim's machine. It sends out download links to all the members in the Yahoo buddy list. Later variants may also spread by Autorun.ini files created on removable drives, so that it may be automatically executed on systems where Autorun is enabled. Overview -This worm spreads by using Yahoo messenger. IM Virus TR/Autoit.AX.1~W32/YahLover.worm ~Yahoo Messenger
0 Comments
Leave a Reply. |