Trojan

Trojan:Win32/Ymacco.AAFA removal instruction

Malware Removal

The Trojan:Win32/Ymacco.AAFA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AAFA virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Ymacco.AAFA?


File Info:

crc32: DA619B05
md5: b1f44825d20472a0eb531029fe6821c4
name: tmpr8ey7tni
sha1: 734ade195f9567fb7234f94f4e9a9abbb0522df9
sha256: fa469335948d537768b4c9de3e72699f1ef458f075f295a972d0821518b564d4
sha512: 5b684fe8db62343eed5778e0683525a58bccf16307e2cda8e0009db430b650b3d134c5d3c48e309da28f739ed8fda99606d85d6d26d8f7cb548fb5bef9d8b129
ssdeep: 6144:/aUPSD6VEJD6Lp7+PTa7wx36Ajeclrh94yv8:/aU06VEt6Zk3Lec1Tk
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2012 - 2019
Assembly Version: 0.0.0.0
InternalName: lokisealed.exe
FileVersion: 8.12.16.20
CompanyName: N&n5dZ7(8q*D^P
Comments: Qn7)8|mC~rX6T
ProductName: 4z~E!Ba72%PoH
ProductVersion: 8.12.16.20
FileDescription: 4z~E!Ba72%PoH
OriginalFilename: lokisealed.exe

Trojan:Win32/Ymacco.AAFA also known as:

MicroWorld-eScanTrojan.Agent.ESAS
FireEyeGeneric.mg.b1f44825d20472a0
McAfeeRDN/Generic.rp
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaBackdoor:MSIL/Kryptik.7e84f25c
K7GWTrojan ( 005685061 )
K7AntiVirusTrojan ( 005685061 )
ArcabitTrojan.Agent.ESAS
BitDefenderThetaGen:NN.ZemsilF.34128.xm0@aWr8eA
F-ProtW32/MSIL_Kryptik.ANE.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Androm.gen
BitDefenderTrojan.Agent.ESAS
NANO-AntivirusTrojan.Win32.Kryptik.hlaoba
Paloaltogeneric.ml
RisingTrojan.Lokibot!1.B343 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.Agent.ESAS (B)
ComodoMalware@#371bhwfuoijc7
F-SecureTrojan.TR/Dropper.MSIL.wuxsk
DrWebTrojan.Siggen9.52795
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.MSIL.WACATAC.THFOIBO
McAfee-GW-EditionRDN/Generic.rp
SophosTroj/MSIL-OXG
IkarusTrojan-Spy.Agent
CyrenW32/MSIL_Kryptik.ANE.gen!Eldorado
AviraTR/Dropper.MSIL.wuxsk
MicrosoftTrojan:Win32/Ymacco.AAFA
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
GDataTrojan.Agent.ESAS
AhnLab-V3Trojan/Win32.Kryptik.R339803
ALYacTrojan.Agent.ESAS
Ad-AwareTrojan.Agent.ESAS
MalwarebytesTrojan.PCrypt.MSIL.Generic
ESET-NOD32a variant of MSIL/Kryptik.WGH
TrendMicro-HouseCallTrojan.MSIL.WACATAC.THFOIBO
TencentWin32.Backdoor.Fareit.Auto
YandexTrojan.Igent.bTSDXd.2
SentinelOneDFI – Malicious PE
FortinetMSIL/Kryptik.WFR!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.95f956
PandaTrj/GdSda.A
Qihoo-360Generic/Backdoor.9cf

How to remove Trojan:Win32/Ymacco.AAFA?

Trojan:Win32/Ymacco.AAFA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment