Malware

About “Program:Win32/Ymacco.AA29” infection

Malware Removal

The Program:Win32/Ymacco.AA29 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AA29 virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Russian

How to determine Program:Win32/Ymacco.AA29?


File Info:

crc32: 191027AF
md5: aaf0f6d6a6c31f9bb213535558768c32
name: AAF0F6D6A6C31F9BB213535558768C32.mlw
sha1: 04c13faa294022b39d72cd1cf53d79e67df6cc3f
sha256: 29baf99436be17dfe39d01841ecd45b2708b5f47a856995d0378177c8df10245
sha512: 9eed15f2d9a4c963f2dcbf4619d2beffdfafeb5e75e789336226e451d4cb045c077aed2b9f3b4f8148f209d51d1fd2873f889ea8bb3f29c4480d1aeab0dc3221
ssdeep: 12288:JAqwiv7+ZI3gfey56g3Z9x+P3zwU89JRqGFnG/UMPEnpsM3y0mh2WXOB9U0VaHbf:JAqw9IanG8MP+00mhT+khNiC
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright SoftwareX Corp 2017
InternalName: SpecS Option Service
FileVersion: 2.0.4.8
CompanyName: SoftX Corp
ProductName: SpecS Option Service
ProductVersion: 2.0.4.8
FileDescription: SpecS Option Service
OriginalFilename: SpecS Option Service
Translation: 0x0009 0x04b0

Program:Win32/Ymacco.AA29 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebAdware.Searcher.3189
CynetMalicious (score: 85)
ALYacGen:Variant.Application.Updater.1
CylanceUnsafe
ZillyaTrojan.Purgen.Win32.275
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Purgen.a8a1cb83
Cybereasonmalicious.6a6c31
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.OpenSUpdater.BO
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Purgen.mc
BitDefenderGen:Variant.Application.Updater.1
NANO-AntivirusTrojan.Win32.Purgen.eynlny
MicroWorld-eScanGen:Variant.Application.Updater.1
TencentWin32.Trojan.Purgen.Lqyi
Ad-AwareGen:Variant.Application.Updater.1
SophosGeneric PUA AE (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!PUP
FireEyeGeneric.mg.aaf0f6d6a6c31f9b
EmsisoftGen:Variant.Application.Updater.1 (B)
WebrootW32.Adware.Installcore
AviraADWARE/FileFinder.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftProgram:Win32/Ymacco.AA29
GDataGen:Variant.Application.Updater.1
AhnLab-V3PUP/Win32.FileFinder.C2443081
McAfeeArtemis!AAF0F6D6A6C3
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Purgen
MalwarebytesPUP.Optional.SpecialSearchOffer
PandaTrj/GdSda.A
RisingRansom.Purgen!8.E539 (CLOUD)
YandexTrojan.GenAsa!N1o0T7nE26M
SentinelOneStatic AI – Suspicious PE
FortinetW32/Purgen.MC!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Purgen.HgIASOYA

How to remove Program:Win32/Ymacco.AA29?

Program:Win32/Ymacco.AA29 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment