Trojan

Trojan.Win32.Yakes.xfba information

Malware Removal

The Trojan.Win32.Yakes.xfba is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Yakes.xfba virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to repeatedly call a single API many times in order to delay analysis time

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Win32.Yakes.xfba?


File Info:

crc32: 0ACC3F9D
md5: 0f5ee9c82173bdf179d5f4c62b42b577
name: 0F5EE9C82173BDF179D5F4C62B42B577.mlw
sha1: b2b17e5d4e16bccc931a8131f941477679f24ec8
sha256: c643dd8f40633edac6f685189c26ed51d3f15e6c8f794c6e339d4581f64e656b
sha512: 678819fb3c980d411529dc6a2d62129012e09b35506a2e82125730129c1568d7c5164853f6a8bfd2c0169405fe78a8a42158d202ca28d564c0eaafa240acda9b
ssdeep: 12288:TO6iRlxwAZxqrWTW+QsPPQLUhApwEvQTK5zPCgUwWJYDpg:xulxwAZxUN5snQLMe+KB1U5wpg
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xc2xa9 1995-Present
InternalName: MethodologyMilojevic
FileVersion: 2.5.6.2
CompanyName: Winstep Software Technologies
FileDescription: Decoding Belarc Freedom Drove
LegalTrademarks: Copyright xc2xa9 1995-Present
Comments: Decoding Belarc Freedom Drove
ProductName: MethodologyMilojevic
Languages: English
ProductVersion: 2.5.6.2
PrivateBuild: 2.5.6.2
OriginalFilename: MethodologyMilojevic
Translation: 0x0409 0x04b0

Trojan.Win32.Yakes.xfba also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.HVNC.15
ALYacTrojan.Ransom.Scarab
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.69283
SangforTrojan.Win32.Yakes.xfba
AlibabaTrojan:Win32/Yakes.a9698f73
K7GWTrojan ( 00538e011 )
K7AntiVirusTrojan ( 00538e011 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJEG
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Yakes.xfba
BitDefenderGen:Variant.Ransom.Scarab.43
NANO-AntivirusTrojan.Win32.Yakes.fhsmxf
MicroWorld-eScanGen:Variant.Ransom.Scarab.43
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Variant.Ransom.Scarab.43
SophosMal/Generic-S
ComodoMalware@#lhfzez0tk4r5
BitDefenderThetaGen:NN.ZexaF.34058.KmKfaWDbiQdi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.hc
FireEyeGeneric.mg.0f5ee9c82173bdf1
EmsisoftGen:Variant.Ransom.Scarab.43 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1104894
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ransom.Scarab.43
GDataGen:Variant.Ransom.Scarab.43
AhnLab-V3Malware/Win32.Generic.C2718822
McAfeeArtemis!0F5EE9C82173
MAXmalware (ai score=97)
VBA32Trojan.Yakes
PandaTrj/GdSda.A
IkarusTrojan.Agent
FortinetW32/Kryptik.GJEG!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Botnet.Yakes.HwsBEpsA

How to remove Trojan.Win32.Yakes.xfba?

Trojan.Win32.Yakes.xfba removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment