Home Malware Programs Viruses W32.Yazz

W32.Yazz

Posted: March 19, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 50
First Seen: March 19, 2013
OS(es) Affected: Windows

W32.Yazz is a virus that affects executable files and downloads potentially malevolent files onto the infected computer. When W32.Yazz is executed, it drops the potentially malevolent files on the corrupted PC. W32.Yazz also creates the UpdateWinTools.5.1 mutex so that only one instance of the virus is run. W32.Yazz creates the registry entries so that it can run automatically every time Windows is started. W32.Yazz searches all drives for executable files and affects them. W32.Yazz then searches network shares and copies corrupted files using the certain file names. W32.Yazz then downloads files from the specific remote locations.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 151.55 KB (151552 bytes)
MD5: 324afe91c48837e74cefc734d3da7110
Detection count: 69
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 20, 2013
%UserProfile%\Application Data\pwrwin.exe File name: %UserProfile%\Application Data\pwrwin.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\ctxmon.exe File name: %Temp%\ctxmon.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\Hello.exe File name: %DriveLetter%\Hello.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\Report.exe File name: %DriveLetter%\Report.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\ReadMe.exe File name: %DriveLetter%\ReadMe.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\Money.exe File name: %DriveLetter%\Money.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%DriveLetter%\Sex.exe File name: %DriveLetter%\Sex.exe
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"yazzz" = "%Temp%\ctxmon.exe" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"atitool" = "%UserProfile%\Application Data\pwrwin.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"atitool" = "%UserProfile%\Application Data\pwrwin.exe"
Loading...