Home Malware Programs Trojans PWSYahoo

PWSYahoo

Posted: March 28, 2006

PWSYahoo is a trojan, which steals Yahoo! Messenger passwords and account details. It sends gathered data to a predetermined e-mail address. PWSYahoo may disable some essential computer tools including the Registry Editor. The trojan automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 nndenb.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemDisableRegistryTools=1HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunMicrosoftPCHealth32=nndenb.exe
Loading...