Trojan

Should I remove “Trojan:Win32/Ymacco.AA59”?

Malware Removal

The Trojan:Win32/Ymacco.AA59 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA59 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Ymacco.AA59?


File Info:

crc32: 960BE397
md5: 7e7130afe38ebb675e2fb694e1f42825
name: upload_file
sha1: 8033c6432aa51f034afd5eaf1ea18a665134f961
sha256: 594af48b4da21f654d0ceadede4257865f96d9ae3b1f2ef4a96298a9385c7b2c
sha512: 1add848d0ca9b6a876f032c28f920cf666c7916eee3f9718cf3f30333afc80c0bf4e9ff6c3c52e035d5f743521f37d9c9537fae0e08f13886f000bdb5d3e0903
ssdeep: 6144:22EDYH4aaPx2v909HPNvg/7K4GHTOmVcdKsXv5o7bKSMwaM0hY:DV5l09lg/7HGqmm0sXv5gKSMwaM0hY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AA59 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.34250030
FireEyeGeneric.mg.7e7130afe38ebb67
McAfeeArtemis!7E7130AFE38E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.34250030
K7GWTrojan ( 0050b2d01 )
K7AntiVirusTrojan ( 0050b2d01 )
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.34250030
KasperskyTrojan-Ransom.Win32.SageCrypt.fjm
AlibabaRansom:Win32/generic.ali2000010
TencentMalware.Win32.Gencirc.10bbe17d
Endgamemalicious (high confidence)
TACHYONRansom/W32.SageCrypt.416256
EmsisoftTrojan.GenericKD.34250030 (B)
F-SecureHeuristic.HEUR/AGEN.1115437
DrWebTrojan.Encoder.32240
ZillyaTrojan.SageCrypt.Win32.204
TrendMicroMal_MiliCry-2t
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
JiangminTrojan.SageCrypt.gg
AviraHEUR/AGEN.1115437
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Ransom]/Win32.SageCrypt
MicrosoftTrojan:Win32/Ymacco.AA59
ArcabitTrojan.Generic.D20A9D2E
ZoneAlarmTrojan-Ransom.Win32.SageCrypt.fjm
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R346410
Acronissuspicious
VBA32Hoax.SageCrypt
ALYacTrojan.GenericKD.34250030
MAXmalware (ai score=82)
Ad-AwareTrojan.GenericKD.34250030
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.GPRG
TrendMicro-HouseCallMal_MiliCry-2t
RisingStealer.Delf!8.415 (CLOUD)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.GPRG!tr
BitDefenderThetaGen:NN.ZexaF.34142.zOW@aGRzm8ii
AVGWin32:Trojan-gen
Qihoo-360Trojan.Generic

How to remove Trojan:Win32/Ymacco.AA59?

Trojan:Win32/Ymacco.AA59 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment