Trojan

About “Trojan:Win32/Ymacco.AA7E” infection

Malware Removal

The Trojan:Win32/Ymacco.AA7E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA7E virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Trojan:Win32/Ymacco.AA7E?


File Info:

crc32: 7523BBC0
md5: c03ed94d612f7c1cf5d5adcd5f8fd46e
name: ppl.exe
sha1: 89246f5864f47aed7fabe7755b51429956808be1
sha256: 7e9c800f7a7cae17a465e02db754af1ef752d437db1bae90f765da3f1b935780
sha512: 2f118f6749ff5e63af8ecdfdeb8bc8ebc2dffe065cc572c2048444f18869c676ca2d4fd0719fe0f3c96bff69333e0ceaf53c45534f499c13e31671a826521d60
ssdeep: 3072:BbV8ypc6Okl4PXB/umkXElAVqBwUqPcqw7GbfbJViOXRy9GDLoN2OexbNcnKKw5m:tVWkABIDvLbHcGD8NsKe5RTHV+
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright @2012
Assembly Version: 2.9.2.0
InternalName: AnarchyGrabber.exe
FileVersion: 0.0.2.0
CompanyName: Mega
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 3.9.2.0
FileDescription: Mega Bundle
OriginalFilename: Wallpaper Engin.exe
Translation: 0x0000 0x04b0

Trojan:Win32/Ymacco.AA7E also known as:

MicroWorld-eScanGen:Variant.MSILPerseus.197198
FireEyeGeneric.mg.c03ed94d612f7c1c
CAT-QuickHealTrojan.IGENERIC
Qihoo-360Generic/Trojan.062
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusPassword-Stealer ( 0055863e1 )
BitDefenderGen:Variant.MSILPerseus.197198
K7GWPassword-Stealer ( 0055863e1 )
Cybereasonmalicious.864f47
BitDefenderThetaGen:NN.ZemsilF.34132.qq2@aKCGcKb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.Agent.RHM
TrendMicro-HouseCallTROJ_GEN.R011C0REQ20
AvastWin32:Trojan-gen
GDataGen:Variant.MSILPerseus.197198
AlibabaTrojan:MSIL/Generic.940ee8a2
Ad-AwareGen:Variant.MSILPerseus.197198
SophosMal/Disteal-D
F-SecureHeuristic.HEUR/AGEN.1127313
TrendMicroTROJ_GEN.R011C0REQ20
EmsisoftGen:Variant.MSILPerseus.197198 (B)
APEXMalicious
CyrenW32/Trojan.XZGS-0259
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1127313
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.MSILPerseus.D3024E
AhnLab-V3Malware/Win32.RL_Generic.C4123697
MicrosoftTrojan:Win32/Ymacco.AA7E
CynetMalicious (score: 85)
MAXmalware (ai score=88)
MalwarebytesSpyware.AnarchyGrabber
IkarusTrojan.MSIL.PSW
PandaTrj/GdSda.A
RisingStealer.Agent!8.C2 (CLOUD)
eGambitPE.Heur.InvalidSig
FortinetMSIL/Agent.D!tr.pws
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Trojan:Win32/Ymacco.AA7E?

Trojan:Win32/Ymacco.AA7E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment