Malware

What is “Program:Win32/Ymacco.AA9E”?

Malware Removal

The Program:Win32/Ymacco.AA9E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AA9E virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Program:Win32/Ymacco.AA9E?


File Info:

crc32: 819D0B68
md5: b0f3a46adf98efb3a9ac7cead9b4fc5a
name: B0F3A46ADF98EFB3A9AC7CEAD9B4FC5A.mlw
sha1: 01b0ece80907f2d9e500ada1cd2d555b782dd3a2
sha256: 9e0cfd00991a3d387a78770a7748418b4d0ab978717f84a399d766b19a971df0
sha512: 22076388da1305e1a9b7ad3257fde95b81118983c95b0025b3a4c848b6703257dbaeaad3da10dab7e66c18fdb7bc015dbf08f20ad0f37543f40e5b448779b6be
ssdeep: 3072:6YcS7/elK+/8OclqVHCWPR02j7UFMuhSNVqTZFnT0urv:z7C8uHCWPRp71uEOrnourv
type: PE32 executable (DLL) (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Program:Win32/Ymacco.AA9E also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.240541
FireEyeGeneric.mg.b0f3a46adf98efb3
McAfeeRDN/Ursnif_Rm3
CylanceUnsafe
AegisLabTrojan.Win32.Deapax.4!c
K7AntiVirusTrojan ( 00573e2a1 )
BitDefenderGen:Variant.Bulz.240541
K7GWTrojan ( 00573e2a1 )
CyrenW32/Trojan.WXCN-3917
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan.Win32.Deapax.ag
AlibabaTrojan:Win32/Deapax.bf5593e0
ViRobotTrojan.Win32.Z.Deapax.135192
Ad-AwareGen:Variant.Bulz.240541
EmsisoftMalCert.A (A)
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Crypt.Agent.bkxis
DrWebTrojan.Gozi.759
McAfee-GW-EditionArtemis!Trojan
SophosGeneric PUA AB (PUA)
IkarusTrojan-Spy.Win32.Ursnif
eGambitUnsafe.AI_Score_95%
AviraTR/Crypt.Agent.bkxis
KingsoftWin32.Troj.Deapax.ag.(kcloud)
MicrosoftProgram:Win32/Ymacco.AA9E
ArcabitTrojan.Bulz.D3AB9D
ZoneAlarmTrojan.Win32.Deapax.ag
GDataWin32.Trojan-Spy.Ursnif.G4H8ST
CynetMalicious (score: 100)
ALYacTrojan.Banker.Gozi
MAXmalware (ai score=88)
MalwarebytesTrojan.Ursnif
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.HHUM
TrendMicro-HouseCallTROJ_GEN.R002H0DKS20
FortinetW32/Deapax.AG!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM40.1.84C4.Malware.Gen

How to remove Program:Win32/Ymacco.AA9E?

Program:Win32/Ymacco.AA9E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment