Malware

Program:Win32/Ymacco.AA1F removal

Malware Removal

The Program:Win32/Ymacco.AA1F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AA1F virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Program:Win32/Ymacco.AA1F?


File Info:

crc32: E623665A
md5: 8fd28b1784eda6b50c4642328e79bc42
name: 8FD28B1784EDA6B50C4642328E79BC42.mlw
sha1: 345552968df30e529e5b13fce075074e0c89366f
sha256: 1f8a234ef7764c06f45c54c16cc933b8c1d111b837c1ecf1cd1b505c1967ff20
sha512: af464e732aa3eb10021b4037c3f21d3d395c5660b00b439907e64b69114823df4e9eeb9e025e2ff476f637084301deb7c039e4d7c975a53bfc1564025635cd47
ssdeep: 6144:Jvd+9DR9L2Y6fGKUjts0/UCLk3+gA5sE5uHdF6vy:TkvIfnMs596S9F6vy
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2016
InternalName: Java Control Panel
FileVersion: 11.121.2.13
Full Version: 11.121.2.13
CompanyName: Oracle Corporation
ProductName: Java(TM) Platform SE 8 U121
ProductVersion: 8.0.1210.13
FileDescription: Java Control Panel
OriginalFilename: javacpl.exe
Translation: 0x0409 0x04b0

Program:Win32/Ymacco.AA1F also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35937877
FireEyeGeneric.mg.8fd28b1784eda6b5
McAfeeGenericRXNE-LU!8FD28B1784ED
CylanceUnsafe
AegisLabHacktool.Win32.Krap.lKMc
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35937877
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZedlaF.34700.ww8@aqjXK@fi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HILY
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyTrojan-Banker.Win32.RTM.hwh
AlibabaTrojanBanker:Win32/Kryptik.a18fed0a
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareTrojan.GenericKD.35937877
EmsisoftTrojan.GenericKD.35937877 (B)
F-SecureTrojan.TR/Crypt.Agent.vhyvp
DrWebTrojan.Inject4.6403
TrendMicroTROJ_GEN.R002C0RLV20
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-R + Mal/EncPk-APV
JiangminTrojan.Banker.RTM.vh
AviraTR/Crypt.Agent.vhyvp
MAXmalware (ai score=87)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftProgram:Win32/Ymacco.AA1F
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D2245E55
ZoneAlarmTrojan-Banker.Win32.RTM.hwh
GDataTrojan.GenericKD.35937877
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.35937877
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0RLV20
TencentWin32.Trojan-banker.Rtm.Eges
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_95%
FortinetW32/Kryptik.HIDC!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Program:Win32/Ymacco.AA1F?

Program:Win32/Ymacco.AA1F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment