Trojan

About “Trojan:Win32/Ymacco.AAC6” infection

Malware Removal

The Trojan:Win32/Ymacco.AAC6 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AAC6 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Deletes its original binary from disk
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Detects VirtualBox through the presence of a registry key
  • Detects VMware through the presence of a file

Related domains:

z.whorecord.xyz
a.tomx.xyz
support.office365excel.org

How to determine Trojan:Win32/Ymacco.AAC6?


File Info:

crc32: 719959AA
md5: 40aa069171e7ce386f53dd07bf39a176
name: upload_file
sha1: 7ce55ae6b103cda201e6f5c40deb8423eb031468
sha256: de034510400de08c5508ad8d236bc533990778cd9867c0a6190a5459cbca6422
sha512: 2bc4294de66a198f0e90e50f9af0fb346e11463b896a87304164f6ccafeb5c65815c5e7b33053c9b5f52a3ff61d5a4956979a30475070d646dbeda4588464ed8
ssdeep: 12288:VkytPw7ey+8pL1kKMC+8ObXjgkiplWihfvq5fmgryTzxw0LTLNV:VkmwKJAL1PnLUXjg3pgynq7UjTpV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ?Microsoft Corp. 1981-1996
InternalName: msswch.exe
FileVersion: 1.0
CompanyName: Microsoft Corporation
ProductName: Microsoft?Windows(TM) Operating System
ProductVersion: 1.0
FileDescription: msswch
OriginalFilename: msswch.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Ymacco.AAC6 also known as:

MicroWorld-eScanTrojan.GenericKD.34250352
McAfeeArtemis!40AA069171E7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agent.b!c
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKD.34250352
K7GWTrojan ( 00547cd01 )
ArcabitTrojan.Generic.D20A9E70
TrendMicroTROJ_FRS.0NA103GT20
ESET-NOD32a variant of Win32/Agent.AAIB
APEXMalicious
KasperskyTrojan-Dropper.Win32.Agent.tesydj
AlibabaTrojan:Win32/fxmjl.7a4dc779
RisingDropper.Agent!8.2F (CLOUD)
Ad-AwareTrojan.GenericKD.34250352
EmsisoftTrojan.Agent (A)
F-SecureTrojan.TR/Agent.fxmjl
DrWebTrojan.SpyBot.710
FortinetW32/Agent.AAIB!tr
FireEyeTrojan.GenericKD.34250352
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
AviraTR/Agent.fxmjl
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Ymacco.AAC6
ZoneAlarmTrojan-Dropper.Win32.Agent.tesydj
AhnLab-V3Dropper/Win32.Agent.C1579685
BitDefenderThetaAI:Packer.65B8C0FF20
ALYacTrojan.GenericKD.34250352
VBA32BScope.Trojan.APosT
TrendMicro-HouseCallTROJ_FRS.0NA103GT20
IkarusTrojan.Win32.Agent
GDataTrojan.GenericKD.34250352
Cybereasonmalicious.171e7c
PandaTrj/CI.A
Qihoo-360Generic/HEUR/QVM16.0.DCE6.Malware.Gen

How to remove Trojan:Win32/Ymacco.AAC6?

Trojan:Win32/Ymacco.AAC6 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment