TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TROJ_YEKTEL.AA
Overview

Malware type: Trojan

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Low

Description: 

This Trojan may be downloaded from remote sites by other malware. It may be downloaded unknowingly by a user when visiting certain malicious Web sites.

It creates folders. It drops copies of itself. It drops files/components. It displays images.

It creates registry entries to enable its automatic execution at every system startup. It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating registry keys/entries.

It creates registry key(s)/entry(ies).

It drops files.

It saves the downloaded files using certain file names. It then executes the downloaded files. As a result, malicious routines of the downloaded files are exhibited on the affected system. It connects to Web sites.

It downloads a file from a certain URL and renames the file when stored in the affected system. It creates mutex(es) to ensure that only one instance of itself is running in memory. It displays fake alerts that warn users of infection. It also displays fake scanning results of the affected system.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jun. 4, 2009 12:03:28 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.