Trojan

Trojan:Win32/Ymacco.AAE1 removal

Malware Removal

The Trojan:Win32/Ymacco.AAE1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AAE1 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Ymacco.AAE1?


File Info:

crc32: 5EB136DC
md5: b63017c0ab810796c6c9ebba1ec4220f
name: tmptpo3u566
sha1: 287da8a652aa6c3cc21f609494ab616cc95cff0f
sha256: e14221c2221fe797627e7523639886d6a7af062ddadba2e38b72b7a22a41c7ca
sha512: 2d0a820f0000fde42d1f4ae5e476151f25cd8ae99049eb12bb91027f32090e07a1349db0a22022cacff959b38070d2f899886d9cec8ee021bb3533e0b6a29ee4
ssdeep: 98304:t2cPK8Wx5OZMvaAt2peWvZ/0cPlrJSckOr88LXx3wDSx:sCKvx5OZSCpey/jlrJSFaXaDSx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: PsnBrute.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: PsnBrute
ProductVersion: 1.0.0.0
FileDescription: PsnBrute
OriginalFilename: PsnBrute.exe
Translation: 0x0000 0x04b0

Trojan:Win32/Ymacco.AAE1 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.34022046
FireEyeGeneric.mg.b63017c0ab810796
CAT-QuickHealTrojan.Wacatac
McAfeeArtemis!B63017C0AB81
CylanceUnsafe
SangforMalware
K7AntiVirusHacktool ( 00568bfc1 )
BitDefenderTrojan.GenericKD.34022046
K7GWHacktool ( 00568bfc1 )
CrowdStrikewin/malicious_confidence_90% (W)
TrendMicroTROJ_GEN.R002C0PFF20
F-ProtW32/AutoIt.RN.gen!Eldorado
APEXMalicious
GDataTrojan.GenericKD.34022046
AlibabaTrojan:MSIL/AutoIt.85e8ae15
ViRobotTrojan.Win32.Z.Agent.5092352
AegisLabHacktool.Win32.Gamehack.3!e
RisingHackTool.BruteForce!8.762 (CLOUD)
Ad-AwareTrojan.GenericKD.34022046
EmsisoftTrojan.GenericKD.34022046 (B)
F-SecureTrojan.TR/PSW.Agent.tfcio
Invinceaheuristic
SophosMal/Generic-S
IkarusTrojan-PSW.Agent
CyrenW32/AutoIt.RN.gen!Eldorado
WebrootW32.Trojan.Gen
AviraTR/PSW.Agent.tfcio
MAXmalware (ai score=82)
Antiy-AVLTrojan[Spy]/Win32.Windigo
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D207229E
MicrosoftTrojan:Win32/Ymacco.AAE1
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZexaF.34130.IoGfaaroHmm
ALYacTrojan.GenericKD.34022046
ESET-NOD32a variant of Win32/PSW.Agent.OKB
TrendMicro-HouseCallTROJ_GEN.R002C0PFF20
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.OKB!tr.pws
AVGWin32:Trojan-gen
Cybereasonmalicious.652aa6
PandaTrj/CI.A
Qihoo-360Generic/HEUR/QVM10.2.EB9C.Malware.Gen

How to remove Trojan:Win32/Ymacco.AAE1?

Trojan:Win32/Ymacco.AAE1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment