Trojan

Trojan:Win32/Ymacco.AA56 removal instruction

Malware Removal

The Trojan:Win32/Ymacco.AA56 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA56 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Attempts to modify Internet Explorer’s start page
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers

Related domains:

down.1230578.com

How to determine Trojan:Win32/Ymacco.AA56?


File Info:

crc32: C2C844E4
md5: 58fb3162f73905e07f8777ca7cfe8c97
name: setpagem.exe
sha1: 48da22a0dccb217501bf65ade7870b58d2024ade
sha256: 563ee97396c60bb7d587d98e95d68109cfe9b0a924860bee678e1e4da196bb64
sha512: 0729baa97aa659ba4cb3d941a30444a354fb52b4631e2d93f386d1ae329ba1172bb2cc5f1256ee78892ed7fb15fc5f05c0add603f4a64cd0b79c02d378376a1e
ssdeep: 24576:knjF4XQKZUBi/PiR6AHW/13K9WEcH2tlIlwSj:knj2gBIHi9WEyH2
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyrightxff08@xff092019
ProductVersion: 1.0.0.0
ProductName: x8f85x52a9x6a21x5757
FileVersion: 1.0.0.0
FileDescription: x8f85x52a9x6a21x5757
Translation: 0x0409 0x04e4

Trojan:Win32/Ymacco.AA56 also known as:

MicroWorld-eScanGen:Variant.Jacard.186582
FireEyeGeneric.mg.58fb3162f73905e0
CAT-QuickHealTrojanDownloader.Agent
McAfeeArtemis!58FB3162F739
ALYacTrojan.Agent.Ymacco
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderGen:Variant.Jacard.186582
K7GWTrojan ( 005612b21 )
K7AntiVirusTrojan ( 005612b21 )
TrendMicroTROJ_GEN.R002C0PF520
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Jacard.186582
KasperskyTrojan-Downloader.Win32.Agent.xxzipi
AlibabaTrojanDownloader:Win32/Heinote.e9ad583f
NANO-AntivirusTrojan.Win32.Delphi.hlckjb
RisingDownloader.Agent!8.B23 (CLOUD)
EmsisoftGen:Variant.Jacard.186582 (B)
ComodoMalware@#1796c996enph1
F-SecureTrojan.TR/Dldr.Agent.tblrm
ZillyaTrojan.Heinote.Win32.10
SophosMal/Generic-S
IkarusTrojan.Win32.Heinote
CyrenW32/Trojan.DLOU-3873
JiangminTrojanDownloader.Agent.fwwd
AviraTR/Dldr.Agent.tblrm
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Agent
ArcabitTrojan.Jacard.D2D8D6
AegisLabTrojan.Win32.Agent.a!c
ZoneAlarmTrojan-Downloader.Win32.Agent.xxzipi
MicrosoftTrojan:Win32/Ymacco.AA56
CynetMalicious (score: 85)
VBA32TrojanDownloader.Agent
Ad-AwareGen:Variant.Jacard.186582
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Heinote.A
TrendMicro-HouseCallTROJ_GEN.R002C0PF520
TencentMalware.Win32.Gencirc.10cdd7bd
YandexTrojan.Heinote!
FortinetW32/Agent.A!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.0dccb2
AvastWin32:Trojan-gen
Qihoo-360Win32/Trojan.Downloader.aba

How to remove Trojan:Win32/Ymacco.AA56?

Trojan:Win32/Ymacco.AA56 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment