Trojan

Trojan:Win32/Ymacco.AA2D removal

Malware Removal

The Trojan:Win32/Ymacco.AA2D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA2D virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to create or modify system certificates

Related domains:

ip-api.com
www.facebook.com

How to determine Trojan:Win32/Ymacco.AA2D?


File Info:

crc32: 664934A0
md5: ee742e9dfe68e5f4633d4d2ef3fce549
name: jvppp.exe
sha1: 268ac787a5186a5e1be68f84efad6092d05fee9e
sha256: 2d1f82ffe2e3ab1a52e3b34e54126ca063cb8b84424138d77338c106950c22ec
sha512: d3e70fe3c0e14ccac8636e4614ead7473e69427a072c8a4634514747b6bf92bf58b474d6af2c5613df8c2a1496e6a6fbc555d2427730972cf168f37a97d5aaec
ssdeep: 6144:Ln13jwHUysp9nIq+mdtKyHjynSLJ3R9HVJhPiBl0058xo4IqitwYl06bsNroS:h3jr9nIodtKyHjz79JPwlh6S4I5tw40
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AA2D also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Razy.703807
FireEyeGeneric.mg.ee742e9dfe68e5f4
McAfeeRDN/Generic Dropper
CylanceUnsafe
BitDefenderGen:Variant.Razy.703807
CrowdStrikewin/malicious_confidence_90% (W)
Invinceaheuristic
F-ProtW32/Agent.BUL.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan.Win32.Fabookie.gj
AlibabaTrojan:Win32/Generic.5f6a7ee7
RisingTrojan.Occamy!8.F1CD (TFE:5:8c8GPC8FG4H)
Ad-AwareGen:Variant.Razy.703807
SophosMal/Generic-S
ComodoMalware@#3m5ije9cb1hjx
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader33.62213
TrendMicroTrojan.Win32.MALREP.THGAABO
FortinetW32/Agent.UAW!tr
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Razy.703807 (B)
IkarusTrojan.Win32.Agent
CyrenW32/Agent.BUL.gen!Eldorado
WebrootW32.Trojan.TR.Dropper
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.DABD3F
ZoneAlarmTrojan.Win32.Fabookie.gj
MicrosoftTrojan:Win32/Ymacco.AA2D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Agent.R340162
Acronissuspicious
ALYacGen:Variant.Razy.703807
VBA32BScope.Trojan.Infospy
MalwarebytesSpyware.PasswordStealer
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Agent.UAW
TrendMicro-HouseCallTrojan.Win32.MALREP.THGAABO
TencentWin32.Trojan.Dropper.Anfo
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
GDataGen:Variant.Razy.703807
BitDefenderThetaGen:NN.ZexaF.34132.xmGfaGR3pynj
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.7a5186
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dropper.45c

How to remove Trojan:Win32/Ymacco.AA2D?

Trojan:Win32/Ymacco.AA2D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment