TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_NUWAR.YH
Overview

Malware type: Worm

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Low

Distribution potential:

Low

Infection Channel 1 : Propagates via email


Description: 

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

WORM_NUWAR.YH Behavior Diagram

Malware Overview

This worm may be downloaded from remote site(s) by other malware. It may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web site(s).

It drops copy(ies) of itself and file(s)/component(s).

It creates and modifies registry entry(ies) to enable its automatic execution at every system startup. It also creates registry key(s)/entry(ies) as part of its installation routine.

It disables console tracing in a command prompt window on Routing and Remote Access Service by creating registry key(s)/entry(ies).

It creates a registry entry to disable Windows Firewall Settings.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jun. 18, 2008 10:37:15 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.