Trojan

Trojan.Win32.Yakes.nume malicious file

Malware Removal

The Trojan.Win32.Yakes.nume is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Yakes.nume virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Mongolian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Writes a potential ransom message to disk
  • Attempts to delete or modify volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings
  • Attempts to ensure mapped drives are available from an elevated prompt or process with UAC enabled
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Yakes.nume?


File Info:

name: F4C5239907A0F3FF3FE1.mlw
path: /opt/CAPEv2/storage/binaries/dd756e0e55118142c77fb72a07f609e1cda247961324de5b41cbe8b7620417a8
crc32: 09FFD3D1
md5: f4c5239907a0f3ff3fe1dbf6d4d824a6
sha1: 001fe3a7eff927967195d718c15f100d959ada5d
sha256: dd756e0e55118142c77fb72a07f609e1cda247961324de5b41cbe8b7620417a8
sha512: 364b99a2961b4376abb3db23e278f10fa817d41a17f4f92fb17381e144120f587c7588acceb9ab00854597c13ecc5a0078c460ade5c799853cfe59140cba08e4
ssdeep: 6144:16Px3soQq7OQFoInUYUyFTWfEM344r73sHgPDCN6TWF9Jtx:16cjnIUYUyFich4rTsHgP06Up
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13964BF3A582070A1CAEFA9B1CEC7CC6C9B10CFB0E6258E1F1D04ED9E5A597499B1D0F5
sha3_384: 8a4274cc8e5ce3976b1231d164d14da6a692c7c2bba6d276f88a864bae16b3f90d9997d5f6a597d620bc7af2f0ace9ff
ep_bytes: 558bec6aff6810a34100681094410064
timestamp: 2004-06-27 03:04:18

Version Info:

CompanyName: Synacast
FileDescription: Atomisation
FileVersion: 199, 227, 31, 130
InternalName: Beeping
LegalCopyright: Absorbers © 2059
OriginalFilename: Wrenches.exe
ProductName: Approve Unmatchable

Trojan.Win32.Yakes.nume also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.1640
FireEyeGeneric.mg.f4c5239907a0f3ff
CAT-QuickHealRansom.TeslaCrypt.WR4
McAfeeGenericR-JAY!F4C5239907A0
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Yakes.2280a8d4
K7GWTrojan ( 004d41c61 )
K7AntiVirusTrojan ( 004d41c61 )
BitDefenderThetaGen:NN.ZexaF.34212.tq3@aOh8xKkG
CyrenW32/Filecoder.CY.gen!Eldorado
SymantecRansom.TeslaCrypt
ESET-NOD32a variant of Win32/Kryptik.DXXK
TrendMicro-HouseCallCryp_HpMyApp
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Yakes.nume
BitDefenderGen:Variant.Ransom.1640
NANO-AntivirusTrojan.Win32.Dwn.dwoyfl
APEXMalicious
TencentMalware.Win32.Gencirc.114c7b69
Ad-AwareGen:Variant.Ransom.1640
SophosML/PE-A + Mal/Tinba-AB
DrWebTrojan.DownLoader16.8784
ZillyaTrojan.Kryptik.Win32.788046
TrendMicroCryp_HpMyApp
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
EmsisoftGen:Variant.Ransom.1640 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ransom.1640
JiangminTrojan.Yakes.vxl
eGambitGeneric.Malware
AviraTR/Crypt.ZPACK.74363
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.14339B5
MicrosoftRansom:Win32/Tescrypt.A
AhnLab-V3Win-Trojan/Lockycrypt.Gen
Acronissuspicious
VBA32BScope.Trojan.Waldek
ALYacGen:Variant.Ransom.1640
AvastWin32:Malware-gen
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.GenAsa!nLnoSap2qK4
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Deshacop.XO!tr
WebrootTrojan.Dropper.Gen
AVGWin32:Malware-gen
Cybereasonmalicious.907a0f
PandaTrj/Genetic.gen

How to remove Trojan.Win32.Yakes.nume?

Trojan.Win32.Yakes.nume removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment