Malware

Program:Win32/Ymacco.AAC5 removal instruction

Malware Removal

The Program:Win32/Ymacco.AAC5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AAC5 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Detects VirtualBox using WNetGetProviderName trick
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

download.onlineappupdater.com
d.likeavirgin.io
ocsp.digicert.com
webcompanion.com
crl4.digicert.com
crl3.digicert.com

How to determine Program:Win32/Ymacco.AAC5?


File Info:

crc32: E53E5A87
md5: ac1c0d6e49709e76f634ff0bd81676d4
name: AC1C0D6E49709E76F634FF0BD81676D4.mlw
sha1: 2f45e303b17d779083b8af222a0c10441aa2f03e
sha256: c5be352cccf056af970a48dd5e5afa23ddc8c5b56c0a10f0573c267bd67a2448
sha512: f70c83feaa3854a8e1dae2a788bc263a03c18ecd05b6481d3c528a2f8322da27b0a8d5cb1061626f8976aa3ffc12ec846e4575fb605ab1a15a1dc288f4be67ae
ssdeep: 1536:KpgpHzb9dZVX9fHMvG0D3XJZ4Romu/dh83IGlf2mBi3nH:IgXdZt9P6D3XJZ45f37OhnH
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Program:Win32/Ymacco.AAC5 also known as:

DrWebTrojan.DownLoad4.14213
CylanceUnsafe
SangforRiskware.Win32.Wacapew.C
K7AntiVirusRiskware ( 0040eff71 )
AlibabaAdWare:Win32/Neoreklami.7a5fe63e
K7GWRiskware ( 0040eff71 )
CyrenW32/Neoreklami.F.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Neoreklami.gen
Paloaltogeneric.ml
SophosTroj/DwnLd-HM
ComodoApplicUnwnt@#24dr42la4orkb
TrendMicroTROJ_GEN.R03BC0PAS21
McAfee-GW-EditionBehavesLike.Win32.Dropper.lc
IkarusTrojan-Downloader.NSIS.Adload
MicrosoftProgram:Win32/Ymacco.AAC5
GridinsoftAdware.Win32.Downloader.oa
AegisLabAdware.Win32.Neoreklami.2!c
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Neoreklami.gen
CynetMalicious (score: 100)
McAfeeArtemis!AC1C0D6E4970
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R03BC0PAS21
FortinetAdware/Neoreklami
AVGWin32:Adware-gen [Adw]
Qihoo-360Win32/Adware.Generic.HoMASOcA

How to remove Program:Win32/Ymacco.AAC5?

Program:Win32/Ymacco.AAC5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment