Malware

About “Program:Win32/Ymacco.AA4F” infection

Malware Removal

The Program:Win32/Ymacco.AA4F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AA4F virus can do?

  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Program:Win32/Ymacco.AA4F?


File Info:

name: 04666300D0D7D97D5F55.mlw
path: /opt/CAPEv2/storage/binaries/4f277cf171c80f8586a92c5de01c93cf8269f8531221a65f33848da871e24d86
crc32: FC440DFA
md5: 04666300d0d7d97d5f55eff70a989a72
sha1: 6bf0793c5efb964db760d2269ee5047e63516524
sha256: 4f277cf171c80f8586a92c5de01c93cf8269f8531221a65f33848da871e24d86
sha512: 95c7370ad58dc4904716a04e3369c0a0188b78bd9e189715d3f41c1c4162332e6e6599b48390a659f5dc0fa996c5efc4ee46461104e4b07a188c595012c23424
ssdeep: 12288:WY+K8CbRrCnzgUg5PJC/pYLmkAvZbeW640Fy8u1SfGXhrjrMoSanD4sKCh+Jv7tv:WYJ8bTUF3ujJjhSm95I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A2F4AE62FAC2C172E8B211718AF947371E39F572472952DB63E02A7D4D683E07D3934A
sha3_384: 0b55010fa153dcc11295d937583384b93b8fdfaea71425ced84fc4a79442b94f7a912b1815224906b450b58489b091db
ep_bytes: e818d20000e989feffff8bff558bec5d
timestamp: 2014-11-26 14:13:12

Version Info:

CompanyName: 边锋云更新
FileDescription: ra2start
FileVersion: 0.0.0.1
InternalName: ra2start
LegalCopyright: yc51
OriginalFilename: ra2start.exe
ProductName: ra2start
ProductVersion: 0.0.0.1
Translation: 0x0009 0x04b0

Program:Win32/Ymacco.AA4F also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Alman.mAYo
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.40364234
ALYacTrojan.GenericKD.40364234
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Agent.Vd5c
K7AntiVirusTrojan ( 0050725b1 )
K7GWTrojan ( 0050725b1 )
Cybereasonmalicious.0d0d7d
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.AAuto.A suspicious
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKD.40364234
NANO-AntivirusTrojan.Win32.Diztakun.dlwxqd
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.40364234 (B)
VIPRETrojan.GenericKD.40364234
McAfee-GW-EditionBehavesLike.Win32.SoftPulse.bh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.04666300d0d7d97d
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataWin32.Application.PSE.112WNVK
MAXmalware (ai score=89)
Antiy-AVLRiskWare[RiskTool]/Win32.Agent
XcitiumMalware@#3lpgx1gng70u6
ArcabitTrojan.Generic.D267E8CA
MicrosoftProgram:Win32/Ymacco.AA4F
GoogleDetected
McAfeeArtemis!04666300D0D7
VBA32Trojan.Diztakun
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09BO23
RisingTrojan.Generic@AI.100 (RDML:f7aEqqYy+T96DL/Xuidw3A)
YandexTrojan.DR.Injector!fIdLXvOUrVo
IkarusTrojan-Dropper.Win32.Injector
MaxSecureTrojan.Malware.8272911.susgen
FortinetW32/Injector.LLWB!tr
BitDefenderThetaGen:NN.ZexaF.36318.Sq0@aaNyp0nG
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Program:Win32/Ymacco.AA4F?

Program:Win32/Ymacco.AA4F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment