Trojan

Trojan:Win32/Ymacco.AA97 removal instruction

Malware Removal

The Trojan:Win32/Ymacco.AA97 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA97 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Ymacco.AA97?


File Info:

crc32: 7CCD6CD7
md5: bfd929820fa7e7c2c53afd0bedacefe4
name: messenger.exe
sha1: fd7b8bba35f54934172f29838cd2b3de5f834bce
sha256: 9787ff4f54d9a667febd98879d966515cedc6c4409edf3acd34671b1fd8d3e06
sha512: f39794fa2d1628f1cb40c001386e130e42159060903d7b56e8b13b288ab8523c0863e0a5f2dd2c8529db73eae0e38b8d26e3d17f2555bde299d7dbc7e3d131ef
ssdeep: 6144:fBaGAAqq8p/1MWuWqEomz3WWy6bacp2yXijWqFL0RvSnWM+S9CTVtB+D1QKeqNT/:0pCAqmHLL1tODHy1vSWs8TvUWh0PkG
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AA97 also known as:

BkavW32.AIDetectVM.malware2
CynetMalicious (score: 85)
FireEyeGeneric.mg.bfd929820fa7e7c2
CAT-QuickHealTrojan.Generic
McAfeeGenericRXKB-GN!BFD929820FA7
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1343907
SangforMalware
K7AntiVirusTrojan ( 0054b4461 )
BitDefenderGen:Variant.Fugrafa.14244
K7GWTrojan ( 0054b4461 )
CrowdStrikewin/malicious_confidence_60% (W)
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Fugrafa.14244
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.7ccd1fe9
AegisLabTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Fugrafa.14244
TencentWin32.Trojan.Generic.Plav
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Fugrafa.14244 (B)
ComodoMalware@#34ez0h4f56ltz
F-SecureHeuristic.HEUR/AGEN.1132257
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R01FC0PFD20
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Agent
JiangminTrojan.Generic.ejwqi
AviraHEUR/AGEN.1132257
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Fugrafa.D37A4
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Ymacco.AA97
AhnLab-V3Malware/Win32.RL_Generic.R303553
VBA32BScope.Trojan.Tiggre
ALYacGen:Variant.Fugrafa.14244
Ad-AwareGen:Variant.Fugrafa.14244
MalwarebytesTrojan.Downloader
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Agent.TQQ
TrendMicro-HouseCallTROJ_GEN.R01FC0PFD20
RisingTrojan.Agent!8.B1E (CLOUD)
YandexTrojan.Agent!kS+CYBUf1UM
FortinetW32/Generic.TQQ!tr
BitDefenderThetaGen:NN.ZexaF.34130.F8Z@aGnJEOki
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.20fa7e
AvastWin32:TrojanX-gen [Trj]
Qihoo-360Generic/Trojan.002

How to remove Trojan:Win32/Ymacco.AA97?

Trojan:Win32/Ymacco.AA97 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment