Trojan

Trojan:Win32/Ymacco.AA91 (file analysis)

Malware Removal

The Trojan:Win32/Ymacco.AA91 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA91 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Mimics icon used for popular non-executable file format
  • Creates a slightly modified copy of itself

How to determine Trojan:Win32/Ymacco.AA91?


File Info:

crc32: 9CAA1396
md5: 9be02f612594c0a6d3e968a08d6f0c1e
name: IMG-3798778934432345987789987890-87674.exe
sha1: b6d621b8da2cbe42d01d413cb7fa1dead0c21917
sha256: 91c8f2961875cc9e46f40ea917b6d83c45301926d88bb8a0af857f3caedcf8bc
sha512: eb0b5453db9689c174af1f9d8591e0e5a22f5be824edadd83f5e87c692b3b3d3c2ccc6e8f3d7b33beea19b96f484434a5241ca8f450263439e9dfe126441de19
ssdeep: 12288:U3N+JFL5L12H5zx5eAS/0YmIIdiNi9vPoDXP5Jwr:U3gvLKZV5eAS/0YzIdCi9XoVJw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AA91 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.734718
FireEyeGeneric.mg.9be02f612594c0a6
CAT-QuickHealTrojan.Multi
ALYacGen:Variant.Razy.734718
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0056c5dd1 )
BitDefenderGen:Variant.Razy.734718
K7GWTrojan ( 0056c5dd1 )
Cybereasonmalicious.12594c
TrendMicroTrojanSpy.Win32.DATACOLLECTORA.USXVPHD20
BitDefenderThetaAI:Packer.5377655D20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Injects.tlw
AlibabaTrojan:Win32/Ymacco.0965a79f
RisingTrojan.Crypto!8.364 (CLOUD)
Ad-AwareGen:Variant.Razy.734718
ComodoTrojWare.Win32.Agent.zvbtg@0
F-SecureTrojan.TR/Crypt.ZPACK.Gen
Invinceaheuristic
SophosMal/Generic-S
IkarusTrojan.Inject
AviraTR/Crypt.ZPACK.Gen
FortinetW32/GenKryptik.EQFJ!tr
ArcabitTrojan.Razy.DB35FE
MicrosoftTrojan:Win32/Ymacco.AA91
CynetMalicious (score: 100)
McAfeeRDN/Generic.grp
MAXmalware (ai score=84)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HFNA
TrendMicro-HouseCallTrojanSpy.Win32.DATACOLLECTORA.USXVPHD20
TencentWin32.Trojan.Injects.Hxzs
SentinelOneDFI – Malicious PE
GDataWin32.Trojan-Stealer.AgentTesla.MLMKUQ
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.PWS.d75

How to remove Trojan:Win32/Ymacco.AA91?

Trojan:Win32/Ymacco.AA91 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment