
EXELDR32.EXE
PROCESS INFORMATION
Process
Name :
Exeldr32.exe
Process
Path : %SYSTEM%\Exeldr32.exe [ C:\Windows\System32\Exeldr32.exe ]
Process
type : Internet
Worm
Malware
Name :
W32.Yaha.T@mm
Alias : I-Worm.Lentin.gen,
W32/Yaha-T, W32/Yaha.T@mm, Yaha.T
Threat
level : Low
Process
Details :
Exeldr32.exe is the main
component dropped by Yaha.T worm. It is
a mass mailing worm uses e-mail addresses stored
in Windows Address book and also collects
addresses from .ht* files to distribute infected
messages. It also spreads through MSN messenger
list, ICQ list and Yahoo pager list.
Yaha.T
arrives as an e-mail attachment with random
message subject and message body. The SMTP server used to
send the emails is chosen either from the
registry or from the list inside the worm body.
If the infected e-mail
attachment is executed, it copies itself to
Windows system folder with multiples file names
as given below. The worm copies with hidden
attribute.
WINTSK32.EXE
EXELDR32.EXE
After that it modifies
the registry to load automatically whenever an
"EXE" file is executed. The registry
key modified will be
HKEY_CLASSES_ROOT\exefile\shell\open\command
It
also modifies registry run section to load
automatically on the next machine start.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
"MicrosoftServiceManager"= C:\%System%\EXELDR32.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
"MicrosoftServiceManager"= C:\%System%\EXELDR32.EXE
When active in memory it
will disable antivirus programs. If you
have deleted the worm file before fixing the
registry entries your applications will NOT work
properly. In that case you can fix the
registry entries using YahaRegFix tool. Instead of
deleting the worm file manually, you can use Solo
trial version to remove Yaha.T worm safely.
How can I protect my
system?
Solo has incorporated
EXELDR32.EXE in its signature file to protect
users from this worm attack. Solo antivirus
registered users are already protected from this
worm. Make sure that you have installed
registered version of Solo Antivirus to protect
your system from all virus threats.
How
to remove this worm?
If
you are already infected with EXELDR32.EXE process,
you can remove it from your computer using Solo
Antivirus software. Solo antivirus can
detect and remove W32.Yaha.T@mm safely.
Use the following link to Download 30 day
trial version of Solo antivirus to
remove viruses from your computer.

Solo anti-virus not only
scans for all viruses, it contains a unique System
Integrity Checker to protect you from
New Internet Worms, Backdoors and
malicious VB, Java Scripts. It also
effectively removes all existing Internet Worms,
File viruses, malicious VBS, Java scripts,
Trojans, Backdoors, boot sector, partition table
and macro viruses.
You can
purchase Solo antivirus using the link 

|