Home Malware Programs Viruses W32.Yazz

W32.Yazz

Posted: March 19, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 50
First Seen: March 19, 2013
OS(es) Affected: Windows

W32.Yazz is a virus that affects executable files and downloads potentially malevolent files onto the infected computer. When W32.Yazz is executed, it drops the potentially malevolent files on the corrupted PC. W32.Yazz also creates the UpdateWinTools.5.1 mutex so that only one instance of the virus is run. W32.Yazz creates the registry entries so that it can run automatically every time Windows is started. W32.Yazz searches all drives for executable files and affects them. W32.Yazz then searches network shares and copies corrupted files using the certain file names. W32.Yazz then downloads files from the specific remote locations.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 151.55 KB (151552 bytes)
MD5: 324afe91c48837e74cefc734d3da7110
Detection count: 69
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 20, 2013
file.exe File name: file.exe
Size: 188.41 KB (188416 bytes)
MD5: d0ac31c6d4da3c3487c6accd6a0f2fa2
Detection count: 68
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 20, 2013
file.exe File name: file.exe
Size: 1.2 MB (1204224 bytes)
MD5: ee04db913253bdc775e867f50ced4b79
Detection count: 67
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 20, 2013
file.exe File name: file.exe
Size: 933.37 KB (933376 bytes)
MD5: bb950a71fb2d0874a28139cd4f25af98
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 20, 2013
file.exe File name: file.exe
Size: 132.09 KB (132096 bytes)
MD5: 1cd123dd494d2aa13f7b4a48fbdb0b11
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 20, 2013
%UserProfile%\Application Data\pwrwin.exe File name: %UserProfile%\Application Data\pwrwin.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\ctxmon.exe File name: %Temp%\ctxmon.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\Hello.exe File name: %DriveLetter%\Hello.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\Report.exe File name: %DriveLetter%\Report.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\ReadMe.exe File name: %DriveLetter%\ReadMe.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\Money.exe File name: %DriveLetter%\Money.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\Sex.exe File name: %DriveLetter%\Sex.exe
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"yazzz" = "%Temp%\ctxmon.exe" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"atitool" = "%UserProfile%\Application Data\pwrwin.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"atitool" = "%UserProfile%\Application Data\pwrwin.exe"
Loading...