Symptoms
- The graphic animation shown below
- The following registry keys: HKEY_CLASSES_ROOT\exefile\shell\open\command
Default with value C:\Recycled\\%%%%.exe %1 %* where %%%% is a random generated string;
- %%%%.exe file in C:\Recycled where %%%% is the same string as above;
- %%%%.txt and %%%%%%%%.dll files in C:\Windows where %%%% is the same as above.
Removal instructions:
Important: You will have to close all applications before running the
tool (including the antivirus shields) and to restart the computer afterwards.
Additionally you'll have to manually delete the infected files located in archives
and the infected messages from your mail client.
The BitDefender AntiYahaa tool does the following:
- it detects all versions of Win32.Yahaa;
- it deletes the files created by Win32.Yahaa;
- it kills the process from memory;
- it repairs the Windows registry.
Analyzed By
Sorin Victor Dudea BitDefender Virus Researcher
SHARE
THIS ON