yaywuvuo.dll

The module yaywuvuo.dll has been detected as a potentially unwanted program by 28 anti-malware scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘MSServer’. According to AVG, this software downloads additional adware offers during setup.
MD5:
fbd2f364b3336565391b559a4511e9b9

SHA-1:
a48fd337bcdb2fa4359bcf3f5dcc5723f580860a

SHA-256:
50840bc30dd3651ee6f449f3e755ce75800ae245e254a6b16fd4f95c35385220

Scanner detections:
28 / 68

Status:
Potentially unwanted

Analysis date:
4/30/2024 3:45:05 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-Trojan/Conhook.57856
5.0.

Avira AntiVirus
ADSPY/Virtumonde.trz
8.2.1.180

Emsisoft A-Squared
Trojan-Downloader.Win32.ConHook!IK
4.5.0.50

avast!
Win32:VunDrop
2014.9-170312

AVG
Downloader.Generic7
2018.0.2441

Bitdefender
Trojan.Generic.2574626
1.0.20.355

Clam AntiVirus
Trojan.Downloader-36019
0.98/17011

Comodo Security
Application.Win32.Adware.Virtumonde
4091

Dr.Web
Trojan.Virtumod.based.11
9.0.1.071

ESET NOD32
Win32/Adware.Virtumonde
11.4922

Fortinet FortiGate
W32/ConHook.PR!tr.dldr
3/12/2017

F-Prot
W32/Downldr2.BYLL
v6.4.5.1.85

F-Secure
Trojan.Generic.2574626
11.2017-12-03_1

G Data
Trojan.Generic.2574626
17.3.19

IKARUS anti.virus
Trojan-Downloader.Win32.ConHook
t3scan.1.1.80.0

K7 AntiVirus
Trojan-Downloader.Win32.ConHook.pr
13.7.10.990

Kaspersky
Trojan.Win32.Monder
14.0.0.-1298

McAfee
generic!bg.eny
5600.6097

Microsoft Security Essentials
Trojan:Win32/Vundo.gen!H
1.163.1557.0

Norman
Vundo.gen245
11.20170312

nProtect
Trojan-Downloader/W32.ConHook.57856
2009.1.8.0

Panda Antivirus
Trj/ConHook.DT
17.03.12.02

Quick Heal
Win32.Trojan.Monder.gen.3
3.17.10.00

Rising Antivirus
Trojan.DL.Win32.Small.ttr
23.00.65.17310

Sophos
Troj/Virtum-Gen
4.51

Trend Micro
TROJ_Generic.DIM
10.465.12

Vba32 AntiVirus
Trojan-Downloader.Win32.ConHook.pr
3.12.12.2

ViRobot
Trojan.Win32.Downloader.57856.AL
2010.3.5.2214

File size:
56.5 KB (57,856 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Windows\System32\yaywuvuo.dll

File PE Metadata
Compilation timestamp:
1/13/2008 7:36:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1038

Entry point:
52, 68, 53, 33, D6, 1B, 2B, D2, 75, 54, EB, 27, 11, 42, FC, 31, D2, 75, 48, 7A, 1C, 3C, 1B, 42, 77, 77, C3, 70, BA, EB, 1E, 29, 4D, 1A, C8, C6, 8E, 3A, EB, 1D, C4, D9, 72, 2B, 79, E1, B8, 3E, 65, 79, 12, 74, E6, 5C, 48, CD, 1F, 5F, 12, 56, C2, 8B, ED, 7A, E9, 12, 50, 54, 23, 83, C4, 04, 5A, 66, 8C, C9, 32, C9, 51, 68, FA, 59, 37, B4, 83, E1, 00, 75, 64, EB, 28, C2, 9D, 23, C4, 7C, F6, B8, 33, C9, 75, 9D, 7A, 19, F9, C8, 24, 6C, 29, 40, 70, 5A, EB, 1C, 0B, 48, 2E, 6E, A0, 5F, DF, D3, 72, 62, 79, E4, C2, 44...
 
[+]

Entropy:
7.4770

Code size:
36 KB (36,864 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
MSServer

Command:
rundll32.exe C:\Windows\System32\yaywuvuo.dll,#1


Remove yaywuvuo.dll - Powered by Reason Core Security