Backdoor

What is “Backdoor:Win32/Ymacco.AA0A”?

Malware Removal

The Backdoor:Win32/Ymacco.AA0A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Ymacco.AA0A virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Ymacco.AA0A?


File Info:

name: 735119ECD0C24C12F21F.mlw
path: /opt/CAPEv2/storage/binaries/0a095835a2a3a3d1fd7bff3e0b207449ee8896dee5184e1da2642eec9328f84b
crc32: 57DA0C3C
md5: 735119ecd0c24c12f21fcd3df399dc7f
sha1: 4e587f71b6c11f2eda5f3850e3aa3a1bee6c5219
sha256: 0a095835a2a3a3d1fd7bff3e0b207449ee8896dee5184e1da2642eec9328f84b
sha512: 782981cbb7a2ab995df8c4e4f974f94143cd8e55c298eaccbd619cf37e1a645a105821897a766a9d439390bdfbd6ee40845dc75c4451a3f3e034d77aa34a68e8
ssdeep: 3072:1rtFwNJpG3Cllni6V7WBjfhQH4VchSTHZ7FZ3L/NKc:ZXwNJpGS+hQH4VchSTHZ7FZ3L/NK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137D3779D766072DFC867C8B2DAA81C64EB6074BB531F8203A16315EDEA4D997CF140F2
sha3_384: 99561e9fc055021dc273eef6f32f785857128a29ca67baa021ae79693995aff8764c89230f5d5fdbdfb519daa8aa2fdf
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-01-24 08:06:03

Version Info:

Translation: 0x0000 0x04b0
Comments: Console Window Hosts
FileDescription: Console Window Hosts
FileVersion: 10.0.18326.1
InternalName: conhost.exe
LegalCopyright: © Microsoft Corporation. All right server...
OriginalFilename: conhost.exe
ProductName: Microsoft ® Windows®Operating System
ProductVersion: 10.0.18326.1
Assembly Version: 10.0.18326.1

Backdoor:Win32/Ymacco.AA0A also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36290957
FireEyeTrojan.GenericKD.36290957
McAfeeRDN/Generic.dx
CylanceUnsafe
SangforBackdoor.Win32.Ymacco.AA0A
AlibabaTrojan:Win32/Generic.e6295730
CrowdStrikewin/malicious_confidence_60% (D)
CyrenW32/Trojan.KZYT-7262
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
BitDefenderTrojan.GenericKD.36290957
Ad-AwareTrojan.GenericKD.36290957
TrendMicroTROJ_GEN.R002C0PLG21
McAfee-GW-EditionRDN/Generic.dx
EmsisoftTrojan.GenericKD.36290957 (B)
Paloaltogeneric.ml
GDataTrojan.GenericKD.36290957
WebrootW32.Malware.Gen
GridinsoftRansom.Win32.Bladabindi.sa
ArcabitTrojan.Generic.D229C18D
ViRobotTrojan.Win32.Z.Agent.131072.GQH
MicrosoftBackdoor:Win32/Ymacco.AA0A
AhnLab-V3Malware/Win32.RL_Generic.C4352523
BitDefenderThetaGen:NN.ZemsilF.34114.im0@aGRhBrb
ALYacTrojan.GenericKD.36290957
MAXmalware (ai score=100)
TrendMicro-HouseCallTROJ_GEN.R002C0PLG21
RisingMalware.Obfus/MSIL@AI.81 (RDM.MSIL:ZOk0qXM//dB+gVfHlMFhSw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7175203.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.cd0c24
PandaTrj/GdSda.A

How to remove Backdoor:Win32/Ymacco.AA0A?

Backdoor:Win32/Ymacco.AA0A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment