TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TROJ_YEKTEL.AA
Solution

Minimum scan engine version needed: 8.700

Pattern file needed: 6.170.07

Pattern release date: Jun 4, 2009


Important note: The "Minimum scan engine" refers to the earliest Trend Micro scan engine version guaranteed to detect this threat. However, Trend Micro strongly recommends that you update to the latest version in order to get comprehensive protection. Download the latest scan engine here.


Solution:

For Windows ME and XP users, before doing any scans, please make sure you disable System Restore to allow full scanning of your computer.

 Step 1: Remove malware files dropped/downloaded by TROJ_YEKTEL.AA  

 Step 2: Restart in Safe Mode  [learn how]

 Step 3:  Delete this registry value  [learn how]

Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.

  • In HKEY_LOCAL_MACHINE\Software\Microsoft\
    Windows\CurrentVersion\Run
    • PAV = "%Program Files%\PAV\pav.exe"

 Step 4:  Delete this registry value  [learn how]

Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.

  • In HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>
    Windows>CurrentVersion>Explorer> Browser Helper Objects
    • {2E59498D-7E44-4452-9044-0973B080B9E8}
  • In HKEY_CLASSES_ROOT\CLSID
    • {2E59498D-7E44-4452-9044-0973B080B9E8}

 Step 5: Search and delete these files  [learn how]

*Note: There may be some component files that are hidden. Please make sure you check the Search Hidden Files and Folders checkbox in the "More advanced options" option to include all hidden files and folders in the search result.

  • %System%\winexplorer.dll
  • %Desktop%\Personal Antivirus.lnk

 Step 6: Search and delete this folder  [learn how]

*Note: Please make sure you check the Search Hidden Files and Folders checkbox in the "More advanced options" option to include all hidden folders in the search result.

  • PAV



Trend Micro offers best-of-breed antivirus and content-security solutions for your corporate network, small and medium business, mobile device or home PC.

For additional information about this threat, see:
Overview
Technical Details

Search a new malware

Tell us how we did. Take our quick survey.