Home Malware Programs Trojans IM-Worm.Win32.Yahos.hl

IM-Worm.Win32.Yahos.hl

Posted: February 18, 2011

IM-Worm.Win32.Yahos.hl is a malicious trojan horse that may represent security risk for the affected computer system and its network environment. IM-Worm.Win32.Yahos.hl will download files to the computer without consent which will lead to security danger. IM-Worm.Win32.Yahos.hl will try to circulate by sending a link that includes a malicious download. IM-Worm.Win32.Yahos.hl also downloads other malware onto the affected system which circulates through removable drives such as USB flash devices. IM-Worm.Win32.Yahos.hl can copy itself across the existing network(s) and enable attackers to obtain remote access to the compromised computer system. Remove IM-Worm.Win32.Yahos.hl before it harms a computer system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\ndl.dl, %Windir%\nvsvc32.exe
    2 %Windir%\wibrf.jpg, %Windir%\wiybr.png

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}NVIDIA driver monitor = "%Windir%\nvsvc32.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...