Trojan

Trojan:Win32/Ymacco.AA35 information

Malware Removal

The Trojan:Win32/Ymacco.AA35 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA35 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
www.zhukl689.xyz
vip79318901.f3322.net
a.tomx.xyz

How to determine Trojan:Win32/Ymacco.AA35?


File Info:

crc32: 90E9D2E5
md5: 953006bbea1261b5d834bff2f4991ba5
name: netstop.exe
sha1: 8fd1542f753cc64125d8bc8511dfad96d12c66fe
sha256: 66451692bb16a9c7de124d85cb3e675cf0942b6d813c90d2ce0e6bde7e1f5ac0
sha512: 6090dbec8849eca8e5e97e32d85a4293de2ac74cfcb754de982956fc6af6799cdc345999ac02543e546bb796c2270f3509b0901fb0b7f4a378b9dad10206b160
ssdeep: 1536:0GOoOFU4RaCVRyIgZSdKDiHy3BIOuFnToIfQb5cFyV6mxAW:01fpPyzTDiHgrutTBfQb5cFq6mxAW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2016
InternalName: NweServer
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: NweServer x5e94x7528x7a0bx5e8f
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: NweServer Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: NweServer.EXE
Translation: 0x0804 0x04b0

Trojan:Win32/Ymacco.AA35 also known as:

MicroWorld-eScanGeneric.Mulinex.07F52407
FireEyeGeneric.mg.953006bbea1261b5
CAT-QuickHealBackdoor.Zegost.29471
McAfeeGenericRXAY-LC!953006BBEA12
CylanceUnsafe
VIPRETrojan.Win32.Redosdru.C (v)
SangforMalware
K7AntiVirusTrojan ( 004f76401 )
BitDefenderGeneric.Mulinex.07F52407
K7GWTrojan ( 004f76401 )
Cybereasonmalicious.bea126
TrendMicroBKDR_ZEGOST.SM40
BitDefenderThetaGen:NN.ZexaF.34126.gq1@au@ZJ4jb
CyrenW32/KillAV.AU.gen!Eldorado
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-6305873-0
GDataGeneric.Mulinex.07F52407
KasperskyTrojan-Downloader.Win32.Tiny.pru
AlibabaTrojanDownloader:Win32/Farfli.9d4bc841
NANO-AntivirusTrojan.Win32.Farfli.epygrm
ViRobotTrojan.Win32.Z.Farfli.98404
AegisLabTrojan.Win32.Tiny.a!c
TencentMalware.Win32.Gencirc.10b3b486
Ad-AwareGeneric.Mulinex.07F52407
EmsisoftGeneric.Mulinex.07F52407 (B)
ComodoTrojWare.Win32.Agent.PDSB@4q3i1w
DrWebTrojan.DownLoader23.52985
ZillyaTrojan.Farfli.Win32.27810
Invinceaheuristic
McAfee-GW-EditionGenericRXAY-LC!953006BBEA12
SophosMal/Generic-S
IkarusTrojan.Win32.Farfli
F-ProtW32/KillAV.AU.gen!Eldorado
JiangminTrojanDownloader.Generic.avhd
AviraHEUR/AGEN.1103148
MAXmalware (ai score=83)
Antiy-AVLTrojan[Downloader]/Win32.AGeneric
Endgamemalicious (high confidence)
ArcabitGeneric.Mulinex.07F52407
ZoneAlarmTrojan-Downloader.Win32.Tiny.pru
MicrosoftTrojan:Win32/Ymacco.AA35
AhnLab-V3Backdoor/Win32.Farfli.C1780249
VBA32Backdoor.Farfli
ALYacGeneric.Mulinex.07F52407
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Farfli.CCV
TrendMicro-HouseCallBKDR_ZEGOST.SM40
RisingBackdoor.Farfli!1.64B3 (CLOUD)
YandexTrojan.Farfli!whOhdAoWc4g
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AC.3CA097!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Downloader.435

How to remove Trojan:Win32/Ymacco.AA35?

Trojan:Win32/Ymacco.AA35 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment