• Home
  • About
  • Lists
  • Freebies And Promotions
  • Downloads
  • Forums
  • Subscribe (RSS)
  • Newsletter
Technize – Be Techdated,
  • Software
  • Misc
  • Security
  • Microsoft
  • Gadgets
  • General
  • Web
  • Open Source

How To Remove infostealer pws-yahmali Virus

Today I got a mail from John stating that he wanted to remove pws-yahmali virus. So I have researched on the removal of this virus. McAfee detection center calls it pws-yahmali trojen and Symantec calls it infostealer.yahmali. It’s risk level is very low. And it’s only a password stealer. It attempts to steal the password of the yahoo messenger (whichever user logs in) and sends to hxxp://www.ilam-mind-makers.com.

How It Infects The System

The Trojan may be downloaded or may arrive in spammed email as one of the following files:

  • %Temp%services.exe
  • %Temp%LSASS.EXE
  • %Temp%SMSS.EXE
  • %Temp%CSRSS.EXE
  • %Temp%WINLOGON.EXE

Once executed, the Trojan creates one of the following file:
%CurrentFolder%[RANDOM FILENAME]

It also creates and modifies some registry keys.

The Trojan specifically checks for Yahoo! Messenger with the following text in the window title:
Yahoo! Messenger with Voice (BETA)

How to remove pws-yahmali

First of all I would strongly suggest that all the users should have a good antivirus installed in their systems so that chance of malware is as less as possible. Here is my article of how to get a 6 months trial of Kaspersky Internet Security.

After scanning with an antivirus, follow the instructions below to remove pws-yahmali completely:

  1. Disable System Restore (How to disable system restore)
  2. Clean all the temporary files on the system. Use CCleaner to clean your system. You can use the third method of cleaning which is described in the following article (How To Edit Run Command History)
  3. Delete the following registry keys: (Go to Start –> Run –> regedit and find the following key and delete it)
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon”shell” = “explorer.exe “C:DOCUME~1ADMINI~1LOCALS~1Temp[ORIGINAL TROJAN FILENAME].exe [RANDOM CHARACTERS]“
  4. Run the following commands: (Go to Start –> Run and copy and paste the following commands one by one):

REG add HKCUsoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced /v HideFileExt /t REG_DWORD /d 1 /f

REG add HKCUsoftwareMicrosoftWindowsCurrentVersionExplorerAdvanced /v ShowSuperHidden /t REG_DWORD /d 0 /f

This is all you have to do. If you are still having problems, please let me know. Also share your experiences in comments

References:

Symantec
McAfee


Got computer/technical problems? Get FREE help from Technize Forums
Posted by Sanix Security, Troubleshooting, Windows Subscribe to RSS feed
« « Make Folder A Drive In My Computer

How To Restore Compressed (Zipped) Folder in Send To Menu » »

4 Comments to “How To Remove infostealer pws-yahmali Virus”

  1. adnan says:
    June 5, 2008 at 12:53 am

    hi
    i just want to know which anitvirus is best nod 32 or any other

  2. adnan says:
    June 5, 2008 at 12:55 am

    i use ur smart antivirus but some time use it can detect virus but it cant remove why this problem

  3. Sanix technize.com says:
    June 8, 2008 at 7:58 pm

    adnan, it’s up to your satisfaction whichever antivirus you like. Anyways, you can see my article about how to get 6 months trial of kaspersky internet security.
    http://www.technize.com/2008/0.....hs-trials/

    And please note that smart antivirus can only detect and remove a few well known viruses. It should not be used as a regular antivirus.

  4. Kelly Davis says:
    October 15, 2008 at 2:01 am

    Hmm, thats all a bit confusing. I got to the part of finding shell or whatever but confused from there. Any help appreciated. Thanks

Leave a Reply

Click here to cancel reply.

Got computer/technical problems? Get FREE help from Technize Forums

Incoming search terms for the article:

infostealer, infostealer virus, seka virus, how to remove infostealer virus, infostealer removal, Trojan-PWS Winlogina, seka exe, how to remove infostealer, remove infostealer virus, PWS Winlogina, remove infostealer, virus infostealer, virus seka, how to remove a infostealer virus, seka trojan, istealer remover, jargon vbs, yahmali, seka virus for folder, how to remove jargon vbs, removing infostealer virus, ym virus removal tool, infostealer exe, infostealer virus removal, remove seka, winlogina, pws virus, remove seka virus, remove trojan virus on my ym, what is seka virus, infostealer yahmali, www vpntool com trojan, how to remove istealer, jargon vbs remover, infoseeker virus, how to remove seka virus, can mcafee clean the infostealer virus, tools remove virus lsass exe, seka ?????, how to remove trojan pws yahmali a(db), delete infostealer virus, how to remove Infostealer from WIndows 7, Infostealer - Removal, how to delete infostealer, istealer 6 remove, jj83j exe, best remove pws online game, whats infostealer, remove istealer, removing ssekua exe, removal tool for trojan pws yahmali a(db), remove an infostealer, remove infoseeker, remove completely infostealer virus, seka exe delete, seka file erease, seka folder virus, seka remover tool, seka remover, seka hidden folder, remove infostealer 6, remove Trojan-PWS Winlogina, Remove the Trojan-PWS Winlogon A virus from your computer free, remove istealer 6, Remove the Trojan-PWS gratis, remove symantec infostealer, remove istealer apps, remove pws winlogon, remove jargon, remove PWS aq, remove infostealer vista 64 bit, remove ym virus csrss, removing jargon vbs avast, remove infostealer from Windows 7, removing jargon vbs, removing infostealer, removing info stealer, removing bank virus, removel tool jargon vbs, remove infostealer virus winlogon

Giveaways

  • eScan Internet Security:
    in 2 days
  • Identity Protector and Password Manager:
    in 9 days
  • PC Tune Up Giveaway:
    in 9 days
  • Wondershare DemoCreator giveaway:
    in 11 days
Keep your computer running smooth with a registry cleaner from ParetoLogic

Translate

Translate to Englishترجمة الى العربية/ArabicVertaal aan het Nederlands/DutchOversetter til Norsk/NorwegianTraduza ao Português/PortugueseПереведите к русскому/RussianPreložiť do slovenčiny/Slovak
Översätta till Svensk/SwedishПереклад на українську/Ukrainian中文翻译/Chinese SimplifiedTulkot uz latviešu/Latvian한국어에게 번역하십시오/KoreanTradueix al català/CatalanÜbersetzen Sie zum Deutsch/German
Μεταφράστε στα ελληνικά/GreekTraduzca al Español/SpanishTraduisez au Français/Frenchहिन्दी अनुवाद करने के लिए/HindiTraduca ad Italiano/Italian日本語に翻訳しなさい /Japanese中文翻译/Chinese Traditional

Popular

  • unmountable_boot_volume fix
  • folder option missing in windows xp
  • hacked websites
  • stellar phoenix password recovery
  • volume control program
  • windows installer service could not be accessed
  • backup windows 7 activation
  • fastest cpu 2010
  • image resizer vista
  • the volume does not contain a recognized file system

Latest queries

  • windows installer service could not be accessed windows 7
  • snagit freeware
  • fp
  • ogacheckcontrol.dll
  • wga crack 1.9.42.0
  • how to delete notification history on facebook
  • Microsoft Error Messages
  • how to fix vulnerabilities
  • rdc 7.0 download
  • Adam Dastmalchi
  • snagit +freeware
  • windows security warning are you sure you want to copy or move files to this folder
  • OGACheckControl.dll.
  • same image search
  • "Windows Installer Service could not be accessed" "windows 7"

Latest Articles

  • Wondershare DemoCreator, Screen Recording Software, Review And Giveaway [10 Licenses]
  • VPNTraffic Free VPN Accounts Giveaway Winners
  • Protecting Your Family’s Data Using Network Attached Storage (NAS)
  • Safe Returner Free License Winners Announced
  • Latest Laptop Trends
  • Tips To Troubleshoot Mobile Broadband & Dongles
  • BullGuard Internet Security 9.0 Lucky Winners Announcement
  • Free VPNTraffic, VPN Service For USA And Japan Giveaway(20 Accounts)
  • Download Free AnyBizSoft PDF to Word Converter 3.0 With Free License Key
  • Top 10 Netbook Computers

Blogroll

  • AT&T Services
  • Fix malware errors
  • IT Support
  • laptop reviews
  • SEO
  • Shopbot-Computers
  • Software Reviews
  • Technize Forums
  • Whats On My PC

Friendly sites

  • 404 Tech Support
  • Canadian Tech Blogger
  • HD Doctor Blog
  • Safe Computing Tips
  • Stylomart
  • System Admin Tools
  • Techskipper
Sitemap | Privacy Policy | RSS
Copyright © 2010 Technize Be Techdated - All Rights Reserved.