Categories: Trojan

How to remove “Trojan.Win32.Yakes.wrez”?

The Trojan.Win32.Yakes.wrez is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Yakes.wrez virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time

How to determine Trojan.Win32.Yakes.wrez?


File Info:

crc32: 6B5A5925md5: d97472fea5b0cc7923000d37d2713fbename: D97472FEA5B0CC7923000D37D2713FBE.mlwsha1: 67d46a83097647bc38c621d0391b7830722d2e58sha256: 8c4a648b7fef1419a793f92ffc9f35f3163acf0892db541e543d21d43d675e69sha512: 32d0528b291c32b52ffa3035a7e9ebb77e174472d6fee98b78821c475f3e6833bcf135e779273b8d3bedc0b6ef2f2d4c34639e994f6f963de14c434bc48a5605ssdeep: 6144:GcX3/zpK6PnEHIzHP4UQsOQozFOKVEOtEQK3fsxIjXBo3wHkh5BtX:bXPTzvcsOyKVErQgBDH4/Xtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9. All rights reserved. ReGen SoftwareFileVersion: 7.7.4.9CompanyName: ReGen SoftwareLegalTrademarks: xa9. All rights reserved. ReGen SoftwareProductName: Sqlaopcnt RackProductVersion: 7.7.4.9FileDescription: Tgglekeys Parametercollection Iaddinpstdeplymentactin Sollentuna PreprocessorOriginalFilename: Sqlaopcnt Rack.exeTranslation: 0x0409 0x04b0

Trojan.Win32.Yakes.wrez also known as:

Bkav W32.AIDetect.malware1
K7AntiVirus Password-Stealer ( 0052f9a71 )
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
ALYac Trojan.GenericKD.40301360
Malwarebytes MachineLearning/Anomalous.100%
Zillya Trojan.Yakes.Win32.68874
Alibaba TrojanPSW:Win32/Yakes.87cab2cc
K7GW Password-Stealer ( 0052f9a71 )
Cybereason malicious.ea5b0c
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Win32/PSW.Delf.OSF
APEX Malicious
Avast Win32:Trojan-gen
ClamAV Win.Packer.MalwareCrypter-6620810-1
Kaspersky Trojan.Win32.Yakes.wrez
BitDefender Trojan.GenericKD.40301360
NANO-Antivirus Trojan.Win32.Yakes.ferxxq
MicroWorld-eScan Trojan.GenericKD.40301360
Tencent Win32.Trojan.Yakes.Wsjs
Ad-Aware Trojan.GenericKD.40301360
Sophos Mal/Generic-S
Comodo Malware@#3lujhu1b28ygj
BitDefenderTheta Gen:NN.ZexaF.34670.yq0@aWx@3kci
McAfee-GW-Edition BehavesLike.Win32.Dropper.fh
FireEye Generic.mg.d97472fea5b0cc79
Emsisoft Trojan.GenericKD.40301360 (B)
Jiangmin Trojan.Yakes.aabo
Avira HEUR/AGEN.1109230
AegisLab Trojan.Win32.Yakes.4!c
ZoneAlarm Trojan.Win32.Yakes.wrez
GData Trojan.GenericKD.40301360
McAfee Artemis!D97472FEA5B0
MAX malware (ai score=88)
VBA32 BScope.Trojan.Yakes
Panda Trj/CI.A
Rising Stealer.Delf!8.415 (CLOUD)
Ikarus Trojan-Ransom.GandCrab
Fortinet W32/GenKryptik.CDWX!tr
AVG Win32:Trojan-gen
Paloalto generic.ml
Qihoo-360 Win32/Botnet.Yakes.HgIASQ4A

How to remove Trojan.Win32.Yakes.wrez?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “Malware.AI.1620571030”?

The Malware.AI.1620571030 is considered dangerous by lots of security experts. When this infection is active,…

2 mins ago

MemScan:Trojan.Prepender.G (file analysis)

The MemScan:Trojan.Prepender.G is considered dangerous by lots of security experts. When this infection is active,…

4 mins ago

Johnnie.5128 (B) removal tips

The Johnnie.5128 (B) is considered dangerous by lots of security experts. When this infection is…

7 mins ago

Malware.AI.3680381880 removal guide

The Malware.AI.3680381880 is considered dangerous by lots of security experts. When this infection is active,…

8 mins ago

What is “Virus.Win32.HLLP.Rile.a”?

The Virus.Win32.HLLP.Rile.a is considered dangerous by lots of security experts. When this infection is active,…

13 mins ago

Trojan:Win32/FakeFolder!pz removal guide

The Trojan:Win32/FakeFolder!pz is considered dangerous by lots of security experts. When this infection is active,…

23 mins ago