









 |
W32/Yahack.A Worm
| Name |
W32/Yahack.A Worm |
| Aliases |
W32.Yahack.A, New Backdoor4-b |
| Discovered on |
October 3, 2007 |
Virus Information - W32/Yahack.A Worm:
W32/Yahack.A is a worm. The worm will infect Windows systems and spreads through email.
The from address of the infected mail will be.
boydreadboy@yahoo.com
The subject of the infected mail will be.
--- .:. BoyDread Full Trojan :) .:. ---
Upon execution, the worm copies itself as UpDateWinc.exe in windows system folder.
It also creates the following files in respective folders.
autorun.inf in the folder which the worm is executed. UpDateWind.exe in windows system folder. LogBoy.log in windows folder.
It modifies the registry at the following locations to load itself during each startup.
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\run
The worm records keystrokes, mouse clicks and title of the active windows and saves in LogBoy.log file. 
|