Trojan

Trojan:Win32/Ymacco.AAC3 removal tips

Malware Removal

The Trojan:Win32/Ymacco.AAC3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AAC3 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Ymacco.AAC3?


File Info:

crc32: 7E1D081B
md5: f001a34284907effccd73401f3c67024
name: 2.exe
sha1: 9646d4bce167034408e00da8e8e0b967c8d824ca
sha256: c3843e4e47fdd596ea21993cb29db052bd6d0393e6bcc62821f12a5552781fec
sha512: 6b5029bfe8ecd4611abacc88415213e3937c0ac9a21114b211bdcbff45dc124758cca73275ea9285775dcc970d9d0bee245c37d64ec082aeb66b3351d2587a24
ssdeep: 3072:tg6LLKkWCmq+ly58UbkyjCUqPjdXPYrGezOkx16oZfl3FQOcXqROUqSdV:tpLHZ8UbkyjCUMXClz5T6oZflO9UqU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileV: 1.0.2.27
Translations: 0x0218 0x0167

Trojan:Win32/Ymacco.AAC3 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34790539
FireEyeGeneric.mg.f001a34284907eff
CAT-QuickHealTrojan.Zenpak
McAfeeRDN/Generic Exploit
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0057149a1 )
BitDefenderTrojan.GenericKD.34790539
K7GWTrojan ( 0057149a1 )
Cybereasonmalicious.ce1670
TrendMicroTrojan.Win32.WACATAC.USMANJG20
CyrenW32/Kryptik.CCB.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Zenpak.gen
AlibabaTrojan:Win32/Ymacco.72d08377
ViRobotTrojan.Win32.Z.Kryptik.199168.FZ
AegisLabTrojan.Win32.Zenpak.4!c
TencentWin32.Trojan.Zenpak.Dyfh
Ad-AwareTrojan.GenericKD.34790539
EmsisoftTrojan.Crypt (A)
ComodoMalware@#2i347rs2diwo2
F-SecureTrojan.TR/AD.ZLoader.sdjto
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraTR/AD.ZLoader.sdjto
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Ymacco.AAC3
ArcabitTrojan.Generic.D212DC8B
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataTrojan.GenericKD.34790539
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MalPe.R353255
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34570.mqW@am4Hb2t
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HGUF
RisingTrojan.Kryptik!1.CBE0 (CLASSIC)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_60%
FortinetPossibleThreat.PALLAS.H
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.fc8

How to remove Trojan:Win32/Ymacco.AAC3?

Trojan:Win32/Ymacco.AAC3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment