Trojan

Should I remove “Trojan:Win32/Ymacco.AAD5”?

Malware Removal

The Trojan:Win32/Ymacco.AAD5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AAD5 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

m.ug065.com

How to determine Trojan:Win32/Ymacco.AAD5?


File Info:

crc32: BC9D7FD8
md5: 1beadb024fb3a1dc958aa64461612a50
name: ______-_________.exe
sha1: 3d3e5c79fa2e0bb27d3a9c5e8c534cdee8787040
sha256: d5293100a3f07b7ac97882e01b86e70c03a7e2a23e098fbce81153015744accd
sha512: 19bb586c658ea5d5aa48799ba3325e5ca9a95ad53321c190eba3c26a066d2d42f8b243b223d7c24e1e5b289cce6b8e1c48da260b5a3ab8f5bc418e9a42f010d7
ssdeep: 24576:A8+wVCg0cUdQ4d1OhUP6dpLxIViI9JY6q/chrLBYB3+f2v/dGPiUZ4be+jPLulM6:AUjiCZIVM6qElKhZdGKvpjPGMyrgM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 1.0.0.0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
Translation: 0x0804 0x04b0

Trojan:Win32/Ymacco.AAD5 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Graftor.717294
FireEyeGeneric.mg.1beadb024fb3a1dc
CAT-QuickHealTrojan.Wacatac
McAfeeArtemis!1BEADB024FB3
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Variant.Graftor.717294
K7GWTrojan ( 00013a151 )
K7AntiVirusTrojan ( 005246d51 )
BitDefenderThetaGen:NN.ZexaF.34132.6r0@aGhsSEpH
F-ProtW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Zusy-6840460-0
GDataWin32.Application.PUPStudio.A
ViRobotTrojan.Win32.Z.Graftor.2007040
Ad-AwareGen:Variant.Graftor.717294
SophosGeneric PUA DN (PUA)
ComodoWorm.Win32.Dropper.RA@1qraug
Invinceaheuristic
EmsisoftGen:Variant.Graftor.717294 (B)
CyrenW32/Agent.EW.gen!Eldorado
JiangminTrojanDropper.Binder.avg
MaxSecureDropper.Dinwod.frindll
MAXmalware (ai score=89)
Antiy-AVLGrayWare/Win32.FlyStudio.a
Endgamemalicious (high confidence)
ArcabitTrojan.Graftor.DAF1EE
MicrosoftTrojan:Win32/Ymacco.AAD5
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Graftor.717294
TrendMicro-HouseCallTROJ_GEN.R002H09G820
RisingMalware.Heuristic!ET#97% (RDMK:cmRtazokKbkRt1dd/kmnOTfGjHVj)
SentinelOneDFI – Malicious PE
eGambitHackTool.Generic
FortinetW32/QQWare.A!tr
Cybereasonmalicious.9fa2e0
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM07.1.608D.Malware.Gen

How to remove Trojan:Win32/Ymacco.AAD5?

Trojan:Win32/Ymacco.AAD5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment