Trojan

How to remove “Trojan.Win32.Yakes.abgsb”?

Malware Removal

The Trojan.Win32.Yakes.abgsb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Yakes.abgsb virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Win32.Yakes.abgsb?


File Info:

name: 513CAC2B193E0FF71EA3.mlw
path: /opt/CAPEv2/storage/binaries/883df975000179593b071a6f5d5ff4deaed1324a36d5595b19edb30fd3ff2cfa
crc32: 21C17A62
md5: 513cac2b193e0ff71ea3dc319a64e994
sha1: 168004b9b8eae37b42e3d9407c3a0cae946c408c
sha256: 883df975000179593b071a6f5d5ff4deaed1324a36d5595b19edb30fd3ff2cfa
sha512: 13bf7a249753444fce2cb5df518a89ef7a05413177620c4bb2f1e2cc9b6baf1c89a1dacaa086cb200ab5236bb3e64a0217bf57b34e22b35c12ddd3bb02b6e401
ssdeep: 49152:bqqtHjonmXm11+N/61VO2czkEwY+0JSlQShJKVzZfQJy7XlxsF:blDOr1UNi1VOmlY/JSDhJKzZfmGxsF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19BD5339BC6574E68F0ABDD74376EFD62856A341E1A486B34DE03EF4683B78E049D2403
sha3_384: b99dc2fe6e5a908b2d0cc7a26cae952709d7913de18a23c429936345261527fdd6ee51c094b14ef113fc0b3f63900391
ep_bytes: 60be00809f008dbe0090a0ff5783cdff
timestamp: 2023-03-15 12:23:02

Version Info:

FileVersion: 1.0.0.0
FileDescription: By 暖心 QQ:1253659669
ProductName: 暖心社区一键配置器
ProductVersion: 1.0.0.0
CompanyName: 暖心
LegalCopyright: 本站游戏仅限休闲娱乐、学习研究! 请勿用于其他商业用途及违法行为! 因此产生的一切后果自行承担,与本网站无关! 下载本站资源应在下载资源的24小时之内删除!
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan.Win32.Yakes.abgsb also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Heur.PWSIME.2
FireEyeGeneric.mg.513cac2b193e0ff7
ALYacGen:Heur.PWSIME.2
MalwarebytesMalware.AI.2370561216
SangforVirus.Win32.Save.a
CrowdStrikewin/grayware_confidence_90% (W)
BitDefenderThetaGen:NN.ZexaF.36132.3oKfaOfHzycb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecTrojan.KillAV
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Trojan.Generic-9779041-0
KasperskyTrojan.Win32.Yakes.abgsb
BitDefenderGen:Heur.PWSIME.2
AvastWin32:PUP-gen [PUP]
EmsisoftGen:Heur.PWSIME.2 (B)
F-SecureHeuristic.HEUR/AGEN.1346696
VIPREGen:Heur.PWSIME.2
TrendMicroTROJ_GEN.R03BC0DD623
McAfee-GW-EditionBehavesLike.Win32.MultiDropper.vc
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan-PSW.QQpass
GDataWin32.Trojan.PSE.15MOKEC
GoogleDetected
AviraHEUR/AGEN.1346696
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.FlyStudio.a
ArcabitTrojan.PWSIME.2
ZoneAlarmTrojan.Win32.Yakes.abgsb
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Avkill.C4865485
McAfeeArtemis!513CAC2B193E
VBA32BScope.Trojan.Download
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DD623
RisingTrojan.Kryptik!8.8 (TFE:5:OQG7dSPB62E)
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.65CA!tr
AVGWin32:PUP-gen [PUP]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Yakes.abgsb?

Trojan.Win32.Yakes.abgsb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment