Home Malware Programs Worms W32.yimfoca.b

W32.yimfoca.b

Posted: December 6, 2010

W32.yimfoca.b (W32.Yimfoca.B) uses instant messaging tools to spread via file/media transfers. This worm can also send malicious spam messages to all your email contacts listed on the infected system. W32.Yimfoca.B connects to a corrupt website and downloads additional threats on the targeted computer. Get rid of W32.Yimfoca.B by using a malware remover which has been updated regularly.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\winrtsnr.txt
    2 C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe
    3 C:\Users\Public\HEX-5823-6893-6818\jutched.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Java Update Manager" = "C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe"HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe" = "C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe:*:Enabled:Java Update Manager"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe" = "C:\Documents and Settings\Administrator\Application Data\HEX-5823-6893-6818\jutched.exe:*:Enabled:Java Update Manager"
Loading...