Home Malware Programs AOL Parasites YahLog

YahLog

Posted: March 28, 2006

YahLog is designed to steal user passwords for Yahoo! Messenger accounts and transfer gathered data to its author. The spyware can also disable certain Windows services and prevent them from starting automatically. It usually affects System Restore Service. YahLog automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 smss.exe
    2 svchost.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicessrserviceStart=4
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666
Loading...