Malware

Program:Win32/Ymacco.AA78 removal guide

Malware Removal

The Program:Win32/Ymacco.AA78 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AA78 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
download.onlineappupdater.com
d.likeavirgin.io
ocsp.digicert.com
d19k2w78yakd9g.cloudfront.net
s.symcd.com
crl4.digicert.com
crl3.digicert.com

How to determine Program:Win32/Ymacco.AA78?


File Info:

crc32: 73C0BE59
md5: 286ecaaaf6e610f419acba165acf128b
name: 286ECAAAF6E610F419ACBA165ACF128B.mlw
sha1: 5ab6ec440f5df404d51f12d423645e1c4831023d
sha256: 781d745f48b6195d80e0aad044932bde1d14d156bffa0e731b1ba00416825dd2
sha512: e37bf75dd2ea61e8aa2aa3cf0cf01425d2979d8ec63be55007931e280af297ee89a286517c79498f001175f0d306bdcbbb99798235f2e5b0287b62af6234dfde
ssdeep: 1536:KpgpHzb9dZVX9fHMvG0D3XJZ4Romu/dNMd/oBnIGlf2mBi3nr:IgXdZt9P6D3XJZ45NRKn7Ohnr
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Program:Win32/Ymacco.AA78 also known as:

McAfeeArtemis!286ECAAAF6E6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabAdware.Win32.Neoreklami.2!c
SangforRiskware.Win32.Wacapew.C
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
CyrenW32/Neoreklami.F.gen!Eldorado
SymantecTrojan.Gen.MBT
BaiduNSIS.Trojan-Downloader.Agent.cw
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.Neoreklami.gen
AlibabaAdWare:Win32/Neoreklami.8d55e8f1
SophosTroj/DwnLd-HM
ComodoApplicUnwnt@#2intxwfxfscsj
DrWebTrojan.DownLoad4.14209
TrendMicroTROJ_GEN.R03BC0PAS21
McAfee-GW-EditionBehavesLike.Win32.Dropper.lc
Antiy-AVLGrayWare[Downloader]/Win32.Adload.gen
MicrosoftProgram:Win32/Ymacco.AA78
GridinsoftTrojan.Win32.Downloader.oa
AhnLab-V3Malware/Win32.Generic.C4320814
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Neoreklami.gen
CynetMalicious (score: 100)
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesAdware.Dropper
TrendMicro-HouseCallTROJ_GEN.R03BC0PAS21
IkarusTrojan-Downloader.NSIS.Adload
FortinetRiskware/Neoreklami
Paloaltogeneric.ml
Qihoo-360Win32/Adware.Generic.HoMASOcA

How to remove Program:Win32/Ymacco.AA78?

Program:Win32/Ymacco.AA78 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment