How to Get Rid of a Trojan Virus That Is Mimicking Internet Explorer
Win32/Yektel is a Trojan virus that mimics Internet Explorer. Win32/Yektel floods your computer with pop-ups stating: "Internet Explorer Warning -- visiting this site may harm your computer." The pop-ups then gives you a link that you can click on for "more secure Internet surfing." Clicking on this link only takes you to a malicious site where Win32/Yektel attempts to trick you into purchasing fake software.
Instructions
-
End Processes
-
1
Press "Ctrl" + "Alt" + "Delete."
-
2
Click on the "Task Manager" and then click on the "Processes" tab.
-
-
3
End the following processes. To end each process, right-click on it and select "End Process."
explorer32.exe
ieupdates.exe
Delete Registry Values
-
4
Hold down the Windows key and press "R." The Run box opens.
-
5
Type "regedit" into the Run box and click "OK." The Registry Editor opens.
-
6
Locate the following registry values in the left pane of the Registry Editor and delete them. To delete a registry value, right-click on it and select "Delete."
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "\ieupdates.exe"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "\explorer32.exe"
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "\winsrc.dll"
HKCR\CLSID\{037C7B8A-151A-49E6-BAED-CC05FCB50328}
Delete DLL Files
-
7
Hold down the Windows key and press "R." The Run box opens.
-
8
Type "cmd" into the Run box and click "OK." The Command Prompt opens.
-
9
Type "regsvr32 /u winsrc.dll" (without the quotation marks) into the Command Prompt and press "Enter."
-
1
References
- Photo Credit wallet and credit cards image by CraterValley Photo from Fotolia.com