Trojan

Trojan:Win32/Ymacco.AA14 removal

Malware Removal

The Trojan:Win32/Ymacco.AA14 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA14 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan:Win32/Ymacco.AA14?


File Info:

crc32: 43714E02
md5: e6e5eb5ea72343702b51a8ea5ba8e14f
name: upload_file
sha1: f9a3ca0a72498dfd6116c4566fd7baf6a28c2025
sha256: 146fb5b594f6b9da202cd0d303548afb1f364ca93c27c44e2f442b1fe26ff77f
sha512: 1e49d0c929043e80c2071c12f695a088e5d7e9b1cbb330b279b54a50f36807f4cd1af61378314d075ea9d9138db03c7d540c2f4cf8a54fe0ef53844cb2a2886b
ssdeep: 6144:22EDYH4aaPx2v909HPNvg/7K4GHTOmicdKsXv5o7bKSMwaM0hY:DV5l09lg/7HGqmP0sXv5gKSMwaM0hY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AA14 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.34249808
FireEyeGeneric.mg.e6e5eb5ea7234370
ALYacTrojan.GenericKD.34249808
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
K7AntiVirusTrojan ( 0050b2d01 )
BitDefenderTrojan.GenericKD.34249808
K7GWTrojan ( 0050b2d01 )
Cybereasonmalicious.ea7234
TrendMicroMal_MiliCry-2t
BitDefenderThetaGen:NN.ZexaF.34142.zOW@aCzK6Ski
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GPRG
TrendMicro-HouseCallMal_MiliCry-2t
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.34249808
KasperskyTrojan-Ransom.Win32.SageCrypt.fje
AlibabaRansom:Win32/generic.ali2000010
TencentMalware.Win32.Gencirc.10bbe17d
Ad-AwareTrojan.GenericKD.34249808
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1115437
DrWebTrojan.Encoder.32240
ZillyaTrojan.SageCrypt.Win32.204
Invinceaheuristic
SentinelOneDFI – Suspicious PE
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.34249808 (B)
APEXMalicious
JiangminTrojan.SageCrypt.gg
AviraHEUR/AGEN.1115437
Antiy-AVLTrojan[Ransom]/Win32.SageCrypt
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D20A9C50
AhnLab-V3Trojan/Win32.Kryptik.R346410
ZoneAlarmTrojan-Ransom.Win32.SageCrypt.fje
MicrosoftTrojan:Win32/Ymacco.AA14
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!E6E5EB5EA723
TACHYONRansom/W32.SageCrypt.416256
VBA32Hoax.SageCrypt
PandaTrj/CI.A
RisingStealer.Delf!8.415 (CLOUD)
MAXmalware (ai score=88)
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.GPRG!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Trojan.Generic

How to remove Trojan:Win32/Ymacco.AA14?

Trojan:Win32/Ymacco.AA14 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment