Trojan

What is “Trojan:Win32/Ymacco.AAC0”?

Malware Removal

The Trojan:Win32/Ymacco.AAC0 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AAC0 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to mimic the file extension of a PDF document by having ‘pdf’ in the file name.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Ymacco.AAC0?


File Info:

crc32: 1CCB844F
md5: d7bd008c1be9e75b0732b38bf08d5fe4
name: Order Inquiry.pdf.exe
sha1: 2e1eba40da2c7667bfcbcb1b01e2766a74ddebd2
sha256: c004bcb9a1b88873e36495a529c5e4614040d66a66880e34ab0d158ad09623a8
sha512: 42e52197a2293f8955113a0321b4e5e7bc57f5068ded9251566e0b5ecd97a8e19a66def458d9813c837ddd848f096fbf42c013443fb7928e6361cca4b1a3f8ac
ssdeep: 384:8cMndsly7cdah19txrnpY0lyY7o4f09LS2NGdX6990P9wsa9Zl4r7I:8FdZAOzpY0lho4MxDNOO9wwH9X27
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Perimedullary1
FileVersion: 1.00
CompanyName: 37signals
ProductName: Lydtryk3
ProductVersion: 1.00
OriginalFilename: Perimedullary1.exe

Trojan:Win32/Ymacco.AAC0 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.75786
FireEyeGeneric.mg.d7bd008c1be9e75b
Qihoo-360Generic/Trojan.cd5
ALYacGen:Variant.Midie.75786
MalwarebytesTrojan.GuLoader
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Variant.Midie.75786
K7GWTrojan ( 005709af1 )
K7AntiVirusTrojan ( 005709af1 )
TrendMicroTrojan.Win32.WACATAC.THJOHBO
BitDefenderThetaGen:NN.ZevbaF.34298.em0@aSWO3qoi
CyrenW32/Bulz.F.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Vebzenpak.aaxs
AlibabaTrojan:Win32/Vebzenpak.eeb060d8
AegisLabTrojan.Multi.Generic.4!c
Ad-AwareGen:Variant.Midie.75786
EmsisoftGen:Variant.Midie.75786 (B)
ComodoMalware@#mvhitv3lob5z
F-SecureTrojan.TR/Kryptik.dkqgs
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.kt
SophosMal/Generic-S
IkarusTrojan.VB.Crypt
JiangminTrojan.Vebzenpak.hsk
WebrootW32.Malware.Gen
AviraTR/Kryptik.dkqgs
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.GenKryptik
MicrosoftTrojan:Win32/Ymacco.AAC0
ArcabitTrojan.Midie.D1280A
ZoneAlarmTrojan.Win32.Vebzenpak.aaxs
GDataWin32.Trojan-Downloader.GuLoader.11JT4P
CynetMalicious (score: 85)
McAfeePWS-FCQZ!D7BD008C1BE9
VBA32TScope.Trojan.VB
CylanceUnsafe
ESET-NOD32a variant of Win32/GenKryptik.ETSA
TrendMicro-HouseCallTrojan.Win32.WACATAC.THJOHBO
RisingDownloader.Guloader!1.CD1C (CLASSIC)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ENNP!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.107817037.susgen

How to remove Trojan:Win32/Ymacco.AAC0?

Trojan:Win32/Ymacco.AAC0 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment