Home Malware Programs Worms IM-Worm.Win32.Yahos.hh

IM-Worm.Win32.Yahos.hh

Posted: February 22, 2011

IM-Worm.Win32.Yahos.hh is a network-aware worm that makes effort to replicate itself across the existing network(s). IM-Worm.Win32.Yahos.hh could request other files from Internet via some URLs. IM-Worm.Win32.Yahos.hh create its startup registry entry in the system to assure it will launch when the computer system is booted. What's worse, ports were open in the corrupted system by IM-Worm.Win32.Yahos.hh. The ports were registered with an attempt to establish connection with the remote hosts. IM-Worm.Win32.Yahos.hh is a serious threat for the PC system, the time it is detected, so the removal should be performed.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\ndl.dl
    2 %Windir%\nvsvc32.exe
    3 %Windir%\wibrf.jpg
    4 %Windir%\wiybr.png

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run]HKEY..\..\..\..{RegistryKeys}NVIDIA driver monitor = "%Windir%\nvsvc32.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Loading...