Yalove.A is a worm that passes itself off as Google's original website. In order to do so, it shows a similar website to the original one in order to deceive users. The results offered in this website could point to malicious websites.

It also connects to certain websites in order to download updates of itself and other malware samples.

Additionally, it carries out several modifications in the Windows Registry, which prevent the user from working with the computer as usual.


These modifications prevent the user from carrying out the following actions, among others:

  • Running files in a fast and straight way, as it disables the option Run from the Start menu.
  • Viewing the processes that are being run through the Task Manager.
  • Modifying the configuration of the features of the folders.
  • Yalove.A reaches the computer in a file that has the icon belonging to a Windows folder. It spreads through local, removable and mapped drives, making copies of itself in them.

    Technical details can be found at this Panda Software page.