Trojan

Should I remove “Trojan:Win32/Ymacco.AAF2”?

Malware Removal

The Trojan:Win32/Ymacco.AAF2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AAF2 virus can do?

  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • Attempts to remove evidence of file being downloaded from the Internet
  • A process attempted to delay the analysis task by a long amount of time.
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
mta6.am0.yahoodns.net
icanhazip.com

How to determine Trojan:Win32/Ymacco.AAF2?


File Info:

crc32: EB15202A
md5: 12280af4e3c41c936b2f06c2f6f70392
name: tmpl00m23rn
sha1: 4882fa7c6fa84fbe0fe245a79dd7aba40a52b8ad
sha256: f2e60b032ad3f5a75821d22aa29e6add71e5ac4f5811fe1ab8a7d4f89ef81a3d
sha512: 91f5c01bda90a4af68203db518148affcbfefbd7450f94beecf006a88ae407dea5d06732ae299d3d61ab07ea02bd572487882d79181f3f1c2c5a2593f2d5ff2a
ssdeep: 384:S+vIT7v23FFnMdQlD/z2SSiQa1D8HB9Tme:S+KQ5SWVDABpme
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AAF2 also known as:

MicroWorld-eScanGeneric.Malware.M!Yd.7EFA1BDD
FireEyeGeneric.mg.12280af4e3c41c93
CAT-QuickHealTrojan.Multi
Qihoo-360Win32/Trojan.BO.651
ALYacTrojan.Agent.Phorpiex
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00556fe51 )
AlibabaTrojanDownloader:Win32/Bitmin.0772d3a5
K7GWTrojan ( 00556fe51 )
Cybereasonmalicious.c6fa84
ArcabitGeneric.Malware.M!Yd.7EFA1BDD
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34128.cuY@aGybbCfi
CyrenW32/Trojan.DVXM-5422
SymantecTrojan Horse
APEXMalicious
AvastWin32:BotX-gen [Trj]
KasperskyTrojan-Downloader.Win32.Bitmin.yfq
BitDefenderGeneric.Malware.M!Yd.7EFA1BDD
Paloaltogeneric.ml
AegisLabTrojan.Multi.Generic.4!c
RisingWorm.Phorpiex!8.48D (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGeneric.Malware.M!Yd.7EFA1BDD (B)
ComodoMalware@#17zfeajclv6x0
F-SecureTrojan.TR/AD.Phorpiex.hiflh
VIPRETrojan.Win32.Generic!BT
TrendMicroWorm.Win32.PHORPIEX.AND
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
AviraTR/AD.Phorpiex.hiflh
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Bitmin
MicrosoftTrojan:Win32/Ymacco.AAF2
ZoneAlarmTrojan-Downloader.Win32.Bitmin.yfq
GDataGeneric.Malware.M!Yd.7EFA1BDD
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R296251
Acronissuspicious
McAfeeGenericRXKR-FV!12280AF4E3C4
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesTrojan.Phorpiex
ESET-NOD32a variant of Win32/Phorpiex.W
TrendMicro-HouseCallWorm.Win32.PHORPIEX.AND
TencentWin32.Trojan-downloader.Bitmin.Dumi
YandexWorm.Phorpiex!rH6iJtqBbVE
IkarusWorm.Win32.Phorpiex
eGambitUnsafe.AI_Score_98%
FortinetW32/Phorpiex.W!tr
Ad-AwareGeneric.Malware.M!Yd.7EFA1BDD
AVGWin32:BotX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Ymacco.AAF2?

Trojan:Win32/Ymacco.AAF2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment