Home Malware Programs Worms Worm.Win32.Ngrbot.eak

Worm.Win32.Ngrbot.eak

Posted: November 2, 2011

Threat Metric

Threat Level: 5/10
Infected PCs: 29
First Seen: November 2, 2011
OS(es) Affected: Windows

Worm.Win32.Ngrbot.eak is a malignant computer worm which can circulate through a PDF vulnerability. Worm.Win32.Ngrbot.eak can also use browser errors, unprotected codes, local channels and removable drives to spread itself. Once installed on the affected computer system, Worm.Win32.Ngrbot.eak cracks passwords to PC user's accounts and can steal personal information. The hacked accounts are used for mass-mailing or instant messaging. Worm.Win32.Ngrbot.eak may download and install additional malware threats. Worm.Win32.Ngrbot.eak may slow your computer. Uninstall Worm.Win32.Ngrbot.eak from the infected machine immediately after detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



Ybxaxy.exe File name: Ybxaxy.exe
Size: 139.26 KB (139264 bytes)
MD5: 7bf95c519f8a215b4dddece2f2d9b0be
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: November 8, 2011
Ybxaxy.exe File name: Ybxaxy.exe
Size: 139.26 KB (139264 bytes)
MD5: f29ff7ebea1d56b8070a2a624f1c4214
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: November 8, 2011
Ybxaxy.exe File name: Ybxaxy.exe
Size: 139.26 KB (139264 bytes)
MD5: 4dd0302c993ccaffcf692181b900c88b
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: November 8, 2011
Ybxaxy.exe File name: Ybxaxy.exe
Size: 139.26 KB (139262 bytes)
MD5: c24d8e2fd01c1739cad1da601e3ab20b
Detection count: 48
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: November 8, 2011
Ybxaxy.exe File name: Ybxaxy.exe
Size: 139.26 KB (139264 bytes)
MD5: 7fc12e795000d1bda3bfdb6d16280f9c
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: November 8, 2011
%System%\alg.exe File name: %System%\alg.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%AppData%\Ybxaxy.exe File name: %AppData%\Ybxaxy.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]Ybxaxy = "%AppData%\Ybxaxy.exe"
Loading...