W32/Yabe.AH Trojan
| Name |
W32/Yabe.AH Trojan |
| Aliases |
TROJ_YABE.AH |
| Discovered on |
November 08, 2006 |
Virus Information - W32/Yabe.AH Trojan:
W32/Yabe.AH is a trojan. The trojan will infect Windows systems.
The trojan will arrive as a downloaded file from the Internet or dropped by other malware. It may also arrive as an attachment along with a spammed email.
Upon execution, the trojan copies itself as ipf.exe in the Windows System folder and winut.dat in the Windows System\drivers folder.
The trojan modifies registry at the following location to load itself during each startup.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The trojan also attempts to download possible malicious files from the following websites.
http://(Blocked)est.de/deutsch/bonn.txt
http://(Blocked)sweb.com/about/more.txt
http://(Blocked)ja-rue.com/mypix/Picture.txt
http://(Blocked)itar.ee/kitarr/efektid/img/link.txt
http://www.(Blocked)rek.netglob.com.pl/stat.txt
http://66.235.(Blocked).21/~academic/img/hor.txt
http://(Blocked)tabane.com/images/sidebar/f02.txt
http://(Blocked)stroyersofevil.com/language/lang_english/lan.txt
This allows the downloaded file to perform its malicious routines on the system.

|