Worm

YahLover.Worm.IM.DDS removal tips

Malware Removal

The YahLover.Worm.IM.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What YahLover.Worm.IM.DDS virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine YahLover.Worm.IM.DDS?


File Info:

name: 049FB72D3A740C7CC0B9.mlw
path: /opt/CAPEv2/storage/binaries/305804e204faf2caa433bb1cfd90ad56688fd14b08eaacafff327b6d9a582c7e
crc32: 1DE0DAB3
md5: 049fb72d3a740c7cc0b9c5064d39c15e
sha1: 26a3465e511988f6c6bdc651b5ee19c569c15ea5
sha256: 305804e204faf2caa433bb1cfd90ad56688fd14b08eaacafff327b6d9a582c7e
sha512: 5d92f8fc1999ae73fea9429ea531011673ddf59ce9ce0733822f1984584dc55ed02b3f0d801cd58be9a6da5d0090949eeb342f514a922eb93f51de44696a492e
ssdeep: 12288:JKtkpMJVfwobPups7YIIw3Jhdieuxq7B5S3C:JENfbPuq7pRJvieux0BUS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125D47B237592A0BEDD71C4FC0A16D73D62A96F24192B654263C02E9B7734D4F4AFE2C2
sha3_384: dd6057a4e239c38bc724e1cb53bc4b1bff5855163d55f308802af7f78bbed7497579b48b5b9635c16a65af71ce1c37a6
ep_bytes: e88ea50000e916feffffcccccccccccc
timestamp: 2007-08-22 07:44:04

Version Info:

Comments: 论坛
FileDescription:
FileVersion: 3, 2, 5, 7
LegalCopyright: 文
Translation: 0x0809 0x04b0
CompiledScript: AutoIt v3 Script : 3, 2, 5, 7

YahLover.Worm.IM.DDS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Autoit.4!c
ClamAVWin.Trojan.Cosmu-2001
FireEyeGeneric.mg.049fb72d3a740c7c
MalwarebytesYahLover.Worm.IM.DDS
SangforTrojan.Win32.Autoit.Vai9
K7AntiVirusTrojan ( 004ba3831 )
AlibabaPacked:Win32/Generic.d7cd6b95
K7GWTrojan ( 004ba3831 )
CrowdStrikewin/malicious_confidence_90% (W)
VirITTrojan.Win32.Generic.APGY
ESET-NOD32Win32/Packed.Autoit.A.Gen suspicious
APEXMalicious
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
F-SecureTrojan.TR/Agent.AutoIt.A.651823.2
ZillyaTrojan.AutoIT.Win32.154741
McAfee-GW-EditionBehavesLike.Win32.Yahlover.jh
Trapminesuspicious.low.ml.score
SophosMal/Generic-S (PUA)
AviraTR/Agent.AutoIt.A.651823.2
MAXmalware (ai score=99)
XcitiumMalware@#3u7y3r56fywku
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeArtemis!049FB72D3A74
VBA32Trojan.Autoit.F
Cylanceunsafe
FortinetW32/Packed_Autoit_A.gen
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.e51198
DeepInstinctMALICIOUS

How to remove YahLover.Worm.IM.DDS?

YahLover.Worm.IM.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment