Malware

Program:Win32/Ymacco.AA5B (file analysis)

Malware Removal

The Program:Win32/Ymacco.AA5B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AA5B virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Program:Win32/Ymacco.AA5B?


File Info:

crc32: 0B13A8D4
md5: e43461dc30ad1b6bf69cf2c1bc171237
name: E43461DC30AD1B6BF69CF2C1BC171237.mlw
sha1: b7f676b6ddd5725c5460c8b085483e74f93b7016
sha256: 5b0a10db89a853ae3464cd30ba1949b36189bf7aae03c069657fe6f9a4b1ba0f
sha512: ac8751691a42895cc52e0565acff46c3e889de5280d47ecbdecad0bffe4ed1ef8266c60d3d18dce88b05c3573382d2c9f3eb6c73952b4cd7c177cc4272ef07d8
ssdeep: 49152:AKM/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb:
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 360.cn Inc. All Rights Reserved.
InternalName: 360DeskAna.exe
FileVersion: 1, 0, 0, 1018
CompanyName: 360.cn
ProductName: 360????
ProductVersion: 1, 0, 0, 1018
FileDescription: 360???? ??????????
OriginalFilename: 360DeskAna.exe
Translation: 0x0804 0x04b0

Program:Win32/Ymacco.AA5B also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.6225
MicroWorld-eScanTrojan.GenericKDZ.71897
FireEyeGeneric.mg.e43461dc30ad1b6b
ALYacTrojan.GenericKDZ.71897
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00574aa51 )
BitDefenderTrojan.GenericKDZ.71897
K7GWTrojan ( 00574aa51 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.34700.d28@aSmyALdj
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Trojan.Generic-9808189-0
KasperskyUDS:DangerousObject.Multi.Generic
AegisLabHacktool.Win32.Krap.lKMc
Ad-AwareTrojan.GenericKDZ.71897
EmsisoftTrojan.GenericKDZ.71897 (B)
F-SecureTrojan.TR/Crypt.Agent.xahux
McAfee-GW-EditionBehavesLike.Win32.Dropper.vt
SophosML/PE-A + Mal/EncPk-APV
JiangminTrojan.Banker.RTM.tc
AviraTR/Crypt.Agent.xahux
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftProgram:Win32/Ymacco.AA5B
GridinsoftTrojan.Win32.Kryptik.oa!s11
ArcabitTrojan.Generic.D118D9
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.GenericKDZ.71897
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R358128
McAfeeGenericRXMZ-SU!E43461DC30AD
VBA32BScope.Backdoor.Vawtrak
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIGG
RisingTrojan.Kryptik!1.CFFC (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM39.1.F77B.Malware.Gen

How to remove Program:Win32/Ymacco.AA5B?

Program:Win32/Ymacco.AA5B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment