Win32/Yaneth [Threat Name] go to Threat

Win32/Yaneth.AA [Threat Variant Name]

Category worm
Size 8704 B
Detection created Oct 16, 2014
Detection database version 10574
Aliases Worm.Win32.Yaneth.7168 (Kaspersky)
  Win32.HLLW.Zackfoo.A (F-Secure)
  Win32.HLLW.Zacker.24576 (Dr.Web)
  Worm:Win32/Zackfoo.A (Microsoft)
Short description

Win32/Yaneth.AA is a worm that spreads by copying itself into certain folders. The file is run-time compressed using PECompact .

Installation

When executed, the worm copies itself into the following location:

  • C:\­Yaneth.exe

The worm creates the following file:

  • C:\­Yaneth.txt

In order to be executed on every system start, the worm sets the following Registry entry:

  • [HKEY_LOCAL_MACHINE\­SOFTWARE\­Microsoft\­Windows\­CurrentVersion\­Run]
    • "Yaneth" = "%malwarefilepath%"
Other information

Win32/Yaneth.AA is a worm that spreads by copying itself into certain folders.


The worm copies itself to the following location:

  • A:\­Yaneth.exe

Please enable Javascript to ensure correct displaying of this content and refresh this page.