Home Malware Programs Trojans Malware.Yero

Malware.Yero

Posted: January 11, 2010

Malware.Yero is a banking Trojan that uses malicious stealth tactics to download harmful files from the Internet. Malware.Yero disables firewalls and steals sensitive financial data like credit card numbers and online banking details. Malware.Yero also takes screen snapshots and downloads additional components before providing a hacker with the remote access to the compromised system. Malware.Yero contains all the characteristics of an identified security risk and should be terminated immediately.

Aliases

Trojan.Win32.Genome.edtb (Kaspersky Lab)
Generic Downloader.x!cb (McAfee)
Trojan-Downloader (Ikarus)
Win-Trojan/Xema.variant (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\wmupdate.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
Loading...