Trojan

Trojan.Ymacco (file analysis)

Malware Removal

The Trojan.Ymacco is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ymacco virus can do?

  • Injection (inter-process)
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Ymacco?


File Info:

crc32: FBDDD630
md5: a32aefef2543e725f6a52af637cf4571
name: tmp4u3bzi2d
sha1: 92daeb6868db1c2d6f275dd8ea01d8fb24c15ce4
sha256: 66f354163032c359f3f3efebb86f56743ccf6656d16fd63eb6ae07b36042ce90
sha512: e3b8e9b5cc21b90eb7fe3df6745a4ef9ad3ca8db04bd90d8ca3118b3bd4e5f41c47ed9ad9612dfc39ddf475d3d597268f3d21de814d2406266aa8c699f65ba4f
ssdeep: 24576:MTdonrt3RcbvooBBHp77vLKbBr9tR8G+IiC7srnFQYc+ebBxGH:MT+nrtqk6HlaBF8G+IDSn6xBY
type: 7-zip archive data, version 0.4

Version Info:

0: [No Data]

Trojan.Ymacco also known as:

MicroWorld-eScanTrojan.GenericKD.43371585
CAT-QuickHealTrojan.Multi
MalwarebytesTrojan.Dropper.SFX
AegisLabTrojan.Win32.Agent.4!e
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Invinceaheuristic
SymantecTrojan.Gen.NPE
ESET-NOD32RAR/Agent.DD
TrendMicro-HouseCallTrojan.AutoIt.PREDATOR.USXVPFF20
AvastOther:Malware-gen [Trj]
KasperskyHEUR:Trojan-Dropper.Win32.Generic
BitDefenderTrojan.GenericKD.43371585
RisingTrojan.Ymacco!8.11BE1 (CLOUD)
Ad-AwareTrojan.GenericKD.43371585
EmsisoftTrojan.GenericKD.43371585 (B)
F-SecureTrojan.TR/Agent.yfrub
TrendMicroTrojan.AutoIt.PREDATOR.USXVPFF20
FireEyeTrojan.GenericKD.43371585
SophosMal/MalitRar-I
CyrenW32/Trojan.ODRX-0142
AviraPO11032020147.exe
MAXmalware (ai score=85)
ArcabitTrojan.Generic.D295CC41
ZoneAlarmHEUR:Trojan-Dropper.Win32.Generic
MicrosoftTrojan:Win32/Ymacco.AA35
CynetMalicious (score: 85)
ALYacTrojan.GenericKD.34054529
VBA32Trojan.Ymacco
ZonerProbably Heur.RARAutorun
TencentWin32.Trojan-dropper.Generic.Ljju
IkarusTrojan.Autoit
MaxSecureTrojan.Malware.300983.susgen
GDataTrojan.GenericKD.43371585
AVGOther:Malware-gen [Trj]

How to remove Trojan.Ymacco?

Trojan.Ymacco removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment