Trojan

Trojan:Win32/Ymacco.AA28 removal guide

Malware Removal

The Trojan:Win32/Ymacco.AA28 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA28 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
greenwester.com

How to determine Trojan:Win32/Ymacco.AA28?


File Info:

crc32: E5313511
md5: ffe12ba80351d8f6eaed89b3d91bb50f
name: upload_file
sha1: d6a1b915a7537535815a1e935cf8d8b30d5de82f
sha256: 28191a5a373b284f577aa1ac1c5895784fc2c274e46b448ab0cd5b9b22e33f30
sha512: 2427e2e946937049454485ecdad4d2f89e5772df0301100532f71dab4fe2ce1d34e10d8011f95842a92e5047ba632e825c074d882ec943722ed885fa676fca92
ssdeep: 12288:fSIEoWR+YkIgyWsl0nSvik+0goa0llbs+c4vfQ8GXW:fSTMYkIgoindo3bsx4vfJGm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AA28 also known as:

MicroWorld-eScanTrojan.GenericKD.43961886
CAT-QuickHealTrojandownloader.Buerak
Qihoo-360Trojan.Generic
ALYacTrojan.GenericKD.43961886
MalwarebytesTrojan.Downloader
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Buerak.a!c
K7AntiVirusTrojan ( 005704151 )
BitDefenderTrojan.GenericKD.43961886
K7GWTrojan ( 005704151 )
ArcabitTrojan.Generic.D29ECE1E
InvinceaMal/Generic-S
CyrenW32/Trojan.GPKU-9369
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/GenCBL.BN
KasperskyHEUR:Trojan-Downloader.Win32.Buerak.gen
AlibabaTrojanDownloader:Win32/GenCBL.e861ce2e
NANO-AntivirusTrojan.Win32.Buerak.hyhcbj
Ad-AwareTrojan.GenericKD.43961886
EmsisoftMalCert-S.CM (A)
ComodoMalware@#7cy64zrylmev
F-SecureTrojan.TR/Redcap.lqzuy
TrendMicroTrojan.Win32.MALREP.THJOGBO
McAfee-GW-EditionGeneric trojan.kj
FireEyeTrojan.GenericKD.43961886
SophosMal/Generic-S
JiangminTrojanDownloader.Buerak.hv
AviraTR/Redcap.lqzuy
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Ymacco.AA28
ViRobotTrojan.Win32.Z.Gencbl.710376
ZoneAlarmHEUR:Trojan-Downloader.Win32.Buerak.gen
GDataTrojan.GenericKD.43961886
CynetMalicious (score: 85)
McAfeeArtemis!FFE12BA80351
VBA32TrojanDownloader.Buerak
CylanceUnsafe
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.Win32.MALREP.THJOGBO
RisingTrojan.MalCert!1.CD11 (CLASSIC)
IkarusTrojan-Banker.Emotet
FortinetW32/Buerak.BN!tr.dldr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]

How to remove Trojan:Win32/Ymacco.AA28?

Trojan:Win32/Ymacco.AA28 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment