TrojanSpy:Win32/Ymacco.AA39 removal tips

Malware Removal

The TrojanSpy:Win32/Ymacco.AA39 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What TrojanSpy:Win32/Ymacco.AA39 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanSpy:Win32/Ymacco.AA39?


File Info:

crc32: EE332A15
md5: 6f9243b35eaecabba30fa98ccbb75321
name: 6F9243B35EAECABBA30FA98CCBB75321.mlw
sha1: a1dcf599323e79ce4c74bcf9566e064b140da03c
sha256: 394a1e9418814e919e577eb70546ef3318018e204cf5df8eca5d96a4a1b93a4d
sha512: cee60fd098481b8078f7ab454fcad436146cdb3dcdbd4139bfd6edff4143f46292dd7ccb83ae8701c5df070213e394a6b0f87fa7499a82167ca4d7930a70f4e6
ssdeep: 1536:P69m4dlKcJWY0HXEp2KOWgkvqvu+OzGT54v1:P6bdlhJWY0NRW3oTa
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2017
Assembly Version: 1.0.0.0
InternalName: Windows Defender.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
ProductName: Windows Defender
ProductVersion: 1.0.0.0
FileDescription: Windows Defender
OriginalFilename: Windows Defender.exe

TrojanSpy:Win32/Ymacco.AA39 also known as:

K7AntiVirusTrojan ( 700000121 )
LionicTrojan.Win32.Hesv.4!c
McAfeeArtemis!6F9243B35EAE
CylanceUnsafe
ZillyaTrojan.ClipBanker.Win32.262
SangforTrojan.Win32.Save.a
AlibabaTrojan:MSIL/ClipBanker.dc08a031
K7GWTrojan ( 700000121 )
Cybereasonmalicious.35eaec
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ClipBanker.CI
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Hesv.arkb
BitDefenderGen:Variant.Bulz.173155
NANO-AntivirusTrojan.Win32.Bcex.equrpm
MicroWorld-eScanGen:Variant.Bulz.173155
TencentWin32.Trojan.Fakedoc.Auto
Ad-AwareGen:Variant.Bulz.173155
SophosMal/Generic-S
ComodoMalware@#1zpbourkdnw5x
BitDefenderThetaGen:NN.ZemsilF.34142.hm0@aq2NzJm
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.6f9243b35eaecabb
EmsisoftGen:Variant.Bulz.173155 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Hesv.haf
AviraTR/ClipBanker.anoxm
eGambitUnsafe.AI_Score_93%
Antiy-AVLTrojan/Generic.ASMalwS.23EB25C
MicrosoftTrojanSpy:Win32/Ymacco.AA39
ArcabitTrojan.Bulz.D2A463
GDataGen:Variant.Bulz.173155
AhnLab-V3HEUR/Fakon.mwf.X1381
MAXmalware (ai score=81)
PandaTrj/GdSda.A
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
YandexTrojan.Bcex!mLXUOAbmXHk
IkarusTrojan.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bcex.ARKB!tr
AVGWin32:Malware-gen

How to remove TrojanSpy:Win32/Ymacco.AA39?

TrojanSpy:Win32/Ymacco.AA39 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

Leave a Comment