Trojan

Trojan:Win32/Yakes.RL!MTB removal guide

Malware Removal

The Trojan:Win32/Yakes.RL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Yakes.RL!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking

Related domains:

z.whorecord.xyz
a.tomx.xyz
makdkvc.ug

How to determine Trojan:Win32/Yakes.RL!MTB?


File Info:

crc32: FF5AF9ED
md5: b8aa6a9fcdac5c78e4896558959d192a
name: soft2.exe
sha1: b57e7b30724f8ffc93bbd97f43caf203f8011a0c
sha256: ee8c877513fbd2d5b779e155b12634c8bbd8f88621b2b3f512ac0002be20329c
sha512: cddaf0f644e925983fbe7c546492326619639af887f39a1eae70dd08d4e2c82c40356c7b214f5f0182396c5beb0fcffdc8528fd598be7bbf254aa8afc6cef617
ssdeep: 24576:gAHnh+eWsN3skA4RV1Hom2KXMmHa8QoWadokKBk5y4l+WE5C6pr6hFN5:Xh+ZkldoPK8Ya8QoqkKBU3c5C60H
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

Trojan:Win32/Yakes.RL!MTB also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33288690
FireEyeGeneric.mg.b8aa6a9fcdac5c78
McAfeeArtemis!B8AA6A9FCDAC
ALYacTrojan.Yakes.Gen
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKD.33288690
K7GWTrojan ( 0055ff9a1 )
K7AntiVirusTrojan ( 0055ff9a1 )
Invinceaheuristic
F-ProtW32/AutoIt.IJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastScript:SNH-gen [Trj]
GDataTrojan.GenericKD.33288690
KasperskyHEUR:Trojan.Script.Generic
AlibabaTrojan:Win32/Injector.263a6cf4
AegisLabTrojan.Script.Generic.4!c
RisingTrojan.Obfus/Autoit!1.C27D (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33288690 (B)
F-SecureHeuristic.HEUR/AGEN.1042841
TrendMicroTROJ_GEN.R020C0PBG20
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
MaxSecureTrojan.Malware.300983.susgen
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
CyrenW32/AutoIt.IJ.gen!Eldorado
AviraHEUR/AGEN.1042841
ArcabitAIT:Trojan.Nymeria.DC36
ZoneAlarmHEUR:Trojan.Script.Generic
MicrosoftTrojan:Win32/Yakes.RL!MTB
Acronissuspicious
MAXmalware (ai score=89)
MalwarebytesSpyware.KpotStealer.AutoIt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.FAU
TrendMicro-HouseCallTROJ_GEN.R020C0PBG20
IkarusTrojan.Win32.Injector
eGambitUnsafe.AI_Score_99%
FortinetAutoIt/Injector.FBO!tr
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.Script.ed4

How to remove Trojan:Win32/Yakes.RL!MTB?

Trojan:Win32/Yakes.RL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment