Yabector-B[adw]

Hi guys,

I recently installed avast on my old laptop, and i found 3 occurences of the virus Yabector-B[adw]

i’ve got 2 questions :

  • if it is an adware virus, how can it be tagged as “high severity” ?
  • Is that possible to get more information about this virus ?

Thanks in advance !!

Bye

Microsoft info
http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=TrojanClicker%3AWin32%2FYabector.gen
http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=TrojanClicker%3AWin32%2FYabector.gen#tab=2

Hi Pondus,

Thanks for your help !
In fact, I had already seen these links. But thank you !
If i understand, Yabector-B doesnt permit someone to take the control of my PC ?

Payload
Notifies remote web server
When run, the installed component checks for the file “%APPDATA%\Desktopicon\config.ini” and creates it if it does not exist. It creates a section within the configuration data file named “[Shortcut]” with content as in the following example:

[Shortcut]
=

The component then starts a Web browser instance (Internet Explorer) and connects to the domain “adon-demand.de” and sends the above content as a string, as in the following example:

adon-demand.de//?s=&c=

Upon visiting the website, the user is then redirected to the online auctioning site “ebay.com”.

Analysis by Dan Kurc

So, no.

Do you commonly get redirected?

Hi Michael,

I dont think so.

Whats the aim of sending the counter ?
adon-demand.de//?s=&c=

I dont understand :smiley:

If you want a check … attach Malwarebytes and OTL diagnostic logs https://forum.avast.com/index.php?topic=53253.0

When done, a malware expert will check those logs and help you fix/remove any issues he see

Make sure you save OTL log as ANSI (not unicode) or it will look chinese

I have deleted with Avast the files :-/

I am thinking of leftover files / anything not detected and crap files that need to ve removed

In other words ?
:-\