Trojan

Trojan:Win32/Ymacco.AA48 (file analysis)

Malware Removal

The Trojan:Win32/Ymacco.AA48 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA48 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Ymacco.AA48?


File Info:

crc32: 1D4CF7B7
md5: ae4121eaf957fc33a84dcb42e2a5ea3c
name: image001.exe
sha1: 160b264dfa6de42a5119757fe987972f80aff698
sha256: 48b7b9c446cb4d7a330d3212af628d2bcfe8a3f2ba9c7308fdf0128bf0194f54
sha512: a6154641a828e8e4350a44e4013142f7df01670829ed15b37e3776d2966b09dd4451532e965d07c9b7111fbb9ea1b4fd6c301cefc606d0d6951e41200c94137d
ssdeep: 12288:Zpx0k6666666666A6666666666v6666666666r6666666666o1Is58eovNJJc:ak6666666666A6666666666v6666666
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright Adobe Systems Inc. 1984-2010
InternalName: Acrobat Distiller
FileVersion: 10.0.0.396
CompanyName: Adobe Systems Incorporated.
ProductName: Adobe Acrobat
ProductVersion: 10.0.0.396
FileDescription: Acrobat Distiller
OriginalFilename: acrodist.exe
Translation: 0x0409 0x04e4

Trojan:Win32/Ymacco.AA48 also known as:

BkavW32.AIDetectVM.malware2
DrWebTrojan.PWS.Banker1.35873
MicroWorld-eScanGen:Variant.Mikey.103874
FireEyeGeneric.mg.ae4121eaf957fc33
Qihoo-360Generic/Trojan.87e
McAfeeGenericRXAA-AA!AE4121EAF957
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0052eef11 )
BitDefenderGen:Variant.Mikey.103874
K7GWTrojan ( 0052eef11 )
TrendMicroTROJ_GEN.R007C0PC120
BitDefenderThetaGen:NN.ZexaCO.34130.Fu0@aeXq18oO
CyrenW32/Trojan.ANRH-3908
SymantecPacked.Generic.534
TrendMicro-HouseCallTROJ_GEN.R007C0PC120
AvastWin32:Trojan-gen
GDataGen:Variant.Mikey.103874
KasperskyTrojan.Win32.Inject.amira
AlibabaTrojan:Win32/GenKryptik.075555c8
NANO-AntivirusTrojan.Win32.Noon.gevmdf
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
EmsisoftGen:Variant.Mikey.103874 (B)
ComodoMalware@#3gqsa5k0rr0cd
F-SecureTrojan.TR/Kryptik.rxeiq
ZillyaTrojan.GenKryptik.Win32.37392
Invinceaheuristic
SophosTroj/AutoG-GK
IkarusTrojan.Win32.Krypt
F-ProtW32/CryptInject.B.gen!Eldorado
JiangminTrojan.Inject.bamw
AviraTR/Kryptik.rxeiq
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.Noon
MicrosoftTrojan:Win32/Ymacco.AA48
ArcabitTrojan.Mikey.D195C2
ZoneAlarmTrojan.Win32.Inject.amira
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.Generic.C3525506
VBA32BScope.TrojanSpy.Noon
ALYacGen:Variant.Mikey.103874
Ad-AwareGen:Variant.Mikey.103874
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/GenKryptik.DVWD
TencentMalware.Win32.Gencirc.116946f5
YandexTrojan.Inject!X44CcpyF1Ds
SentinelOneDFI – Suspicious PE
FortinetW32/GenKryptik.DVWD!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.1728101.susgen

How to remove Trojan:Win32/Ymacco.AA48?

Trojan:Win32/Ymacco.AA48 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment