Trojan

What is “Trojan.Win32.Yakes.mejn”?

Malware Removal

The Trojan.Win32.Yakes.mejn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Yakes.mejn virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (134 unique times)
  • The binary likely contains encrypted or compressed data.
  • Exhibits behavior characteristic of Kovter malware
  • Executed a process and injected code into it, probably while unpacking
  • Detects VirtualBox through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a registry key or value with NUL characters to avoid detection with regedit
  • Installs itself for autorun at Windows startup
  • Stores JavaScript or a script command in the registry, likely for persistence or configuration
  • Attempts to identify installed analysis tools by registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a file
  • Detects VirtualBox through the presence of a registry key
  • Detects VMware through the presence of a file
  • Detects VMware through the presence of a registry key
  • Detects Virtual PC through the presence of a file
  • Attempts to modify browser security settings
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Yakes.mejn?


File Info:

crc32: BE625E52
md5: 008769c620b804d401393fc5721bf34f
name: 008769C620B804D401393FC5721BF34F.mlw
sha1: 9eda95ab88e51e339f7bdce1512235be7cf57414
sha256: 055dca003a76ab4d3701f2351d9298949f8f2df0e4aba4a68bc76f90a2e1225b
sha512: 5bc440aab28726dec7fa9a92b0baafe217143cf2570a7a47a475d03fbb53f65d82170b716ac835ec758e41dacdf787cf53ec698ef42629d244b54868f7705ab1
ssdeep: 12288:5LkhHMC4Ia442DicPS3W7XOjvAyZ/Q4BxW/LTrC:5Lkda4Dic6g+jICQP/LC
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Beepa Pty Ltd 2013
FileVersion: 3.5.99.15619
CompanyName: Beepa Pty Ltd
LegalTrademarks: Fraps is a trademark of Beepa Pty Ltd
ProductName: FRAPS
ProductVersion: 3.5.99.15619
FileDescription: Fraps
Translation: 0x0409 0x04b0

Trojan.Win32.Yakes.mejn also known as:

K7AntiVirusTrojan ( 0056e9301 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop6.3201
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Generic.B4
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.39186
SangforTrojan.Win32.Yakes.mejn
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Yakes.2b3dc9de
K7GWTrojan ( 0056e9301 )
Cybereasonmalicious.b88e51
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Kovter.C
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Yakes.mejn
NANO-AntivirusTrojan.Win32.Yakes.dwvpje
ViRobotTrojan.Win32.Z.Zusy.532008
TencentMalware.Win32.Gencirc.10c5dbc1
SophosMal/Generic-S
ComodoMalware@#617b4z7htm8
BitDefenderThetaGen:NN.ZexaF.34688.Gu1@aewGMibi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PDU21
McAfee-GW-EditionBehavesLike.Win32.Swizzor.hc
FireEyeGeneric.mg.008769c620b804d4
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Yakes.adqx
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1113279
Antiy-AVLTrojan/Generic.ASMalwS.1453FA5
MicrosoftTrojan:Win32/Kovter!rfn
AegisLabTrojan.Win32.Yakes.4!c
GDataWin32.Trojan.Kovter.CGXALJ
AhnLab-V3Trojan/Win32.ZBot.R164684
Acronissuspicious
McAfeeGeneric.dqq
MAXmalware (ai score=100)
VBA32Trojan.Yakes
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PDU21
RisingTrojan.Kovter!8.152 (CLOUD)
YandexTrojan.Yakes!XIfzcuAxiM8
IkarusTrojan.Win32.Kovter
FortinetW32/Generic.AC.2A0E90!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan.Win32.Yakes.mejn?

Trojan.Win32.Yakes.mejn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment