Malware

What is “Program:Win32/Ymacco.AAC1”?

Malware Removal

The Program:Win32/Ymacco.AAC1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AAC1 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Program:Win32/Ymacco.AAC1?


File Info:

crc32: 93324470
md5: 5df1189ec0e6e8959006985f65a487f0
name: 5DF1189EC0E6E8959006985F65A487F0.mlw
sha1: 7001d787883cab774fe8c1f5f6ad0dd3f8f8d727
sha256: c1b09a0ea2dd36202b53d71b52049fdb0ec1b7d6f5ad9fd157813c8807543459
sha512: ff1ed61a0093d9da656322698ad151ffb9318c3b0b33ae20a9d7de219583f934ea2514485c3421911bde3ee33bd5c353fdba389b014609147b196ed1bbf29343
ssdeep: 49152:1KF/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb:
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2014 AVG Technologies CZ, s.r.o.
InternalName: AvDump32
FileVersion: 17.3.3443.0
CompanyName: AVG Technologies CZ, s.r.o.
ProductName: AVG Internet Security System
ProductVersion: 17.3.3443.0
FileDescription: AVG Dump Process
OriginalFilename: AvDump32.exe
Translation: 0x0409 0x04b0

Program:Win32/Ymacco.AAC1 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.6278
MicroWorld-eScanGen:Variant.Zusy.356932
FireEyeGeneric.mg.5df1189ec0e6e895
McAfeeGenericRXMZ-SU!5DF1189EC0E6
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Zusy.356932
K7GWTrojan ( 00574aa51 )
K7AntiVirusTrojan ( 00574aa51 )
BitDefenderThetaGen:NN.ZedlaF.34700.c68@a46KJcdi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0RLG20
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Trojan.Generic-9808189-0
KasperskyUDS:DangerousObject.Multi.Generic
RisingTrojan.Kryptik!1.CFFC (CLASSIC)
Ad-AwareGen:Variant.Zusy.356932
EmsisoftTrojan.Crypt (A)
McAfee-GW-EditionBehavesLike.Win32.Dropper.vt
SophosML/PE-A + Mal/EncPk-APV
IkarusWin32.Outbreak
MAXmalware (ai score=89)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftProgram:Win32/Ymacco.AAC1
GridinsoftTrojan.Win32.Kryptik.oa!s12
ArcabitTrojan.Zusy.D57244
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Zusy.356932
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R358128
VBA32BScope.Backdoor.Vawtrak
ALYacGen:Variant.Zusy.356932
MalwarebytesBackdoor.Qbot
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HIGG
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM39.1.F8A7.Malware.Gen

How to remove Program:Win32/Ymacco.AAC1?

Program:Win32/Ymacco.AAC1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment