Trojan

About “Trojan.Win32.Yakes.wvsi” infection

Malware Removal

The Trojan.Win32.Yakes.wvsi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Yakes.wvsi virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan.Win32.Yakes.wvsi?


File Info:

crc32: 3F2C7887
md5: ee0d8885ef449753d45ce16c16fe947a
name: EE0D8885EF449753D45CE16C16FE947A.mlw
sha1: 19f8893f71084e55076a3968744ce2f61882bd1a
sha256: 8bd3a1ca91e92497243af7236dc301b377f2e97fba3c86b7659a93c5cbd98be8
sha512: 1ddd849e60077ba07898aad62f6981ed6569ae47d0771c60cbbbd55a0755ff64511e6fed53213aa90c61aac11e631fa893b8b2da1dd9f36695ef51f18678b7ad
ssdeep: 24576:8aQ36gOWDA5owuwm9Ik3+40ya7SL7CmZTKCTd8TgKe9:8336gHC+wm9fO40X7E7CwWoKcKo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Spencer Kimball, Peter Mattis and the GIMP Development Team 2016 All rights reserved.
InternalName: Synchronous Antivir
FileVersion: 2.5.5.3
CompanyName: Spencer Kimball, Peter Mattis and the GIMP Development Team
FileDescription: Virus Operation Touchpad Deletemsgs
Comments: Virus Operation Touchpad Deletemsgs
ProductName: Synchronous Antivir
ProductVersion: 2.5.5.3
PrivateBuild: 2.5.5.3
OriginalFilename: Synchronous Antivir
Translation: 0x0409 0x04b0

Trojan.Win32.Yakes.wvsi also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004b39e91 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.858
CynetMalicious (score: 100)
ALYacTrojan.Yakes.Gen
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.131530
SangforTrojan.Win32.GenericKD.31127862
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Yakes.be786249
K7GWTrojan ( 004b39e91 )
Cybereasonmalicious.5ef449
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.Shade.B
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Yakes.wvsi
BitDefenderGen:Variant.Ransom.Ryuk.5
NANO-AntivirusTrojan.Win32.Yakes.fidgre
MicroWorld-eScanGen:Variant.Ransom.Ryuk.5
TencentWin32.Trojan.Yakes.Akoz
Ad-AwareGen:Variant.Ransom.Ryuk.5
SophosMal/Generic-S
ComodoMalware@#dacip8v6tb3b
F-SecureHeuristic.HEUR/AGEN.1126935
BitDefenderThetaGen:NN.ZexaF.34670.Hv0@aCitZFoi
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroPossible_HPGen-38
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.ee0d8885ef449753
EmsisoftGen:Variant.Ransom.Ryuk.5 (B)
JiangminTrojan.Yakes.aaqt
AviraHEUR/AGEN.1126935
Antiy-AVLTrojan/Win32.Yakes
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Troldesh.A
ArcabitTrojan.Ransom.Ryuk.5
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmTrojan.Win32.Yakes.wvsi
GDataGen:Variant.Ransom.Ryuk.5
AhnLab-V3Malware/Win32.Possible_hpgen.C2635853
McAfeeArtemis!EE0D8885EF44
MAXmalware (ai score=100)
VBA32BScope.Trojan.Dynamer
MalwarebytesRansom.Troldesh
PandaTrj/GdSda.A
TrendMicro-HouseCallPossible_HPGen-38
RisingRansom.Troldesh!8.5D1 (CLOUD)
YandexTrojan.Yakes!JZeL6G7boCA
IkarusTrojan-Ransom.FileCrypter
FortinetW32/GenKryptik.CGGM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Botnet.Yakes.HwkAhRsA

How to remove Trojan.Win32.Yakes.wvsi?

Trojan.Win32.Yakes.wvsi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment