Malware

Program:Win32/Ymacco.AACB removal

Malware Removal

The Program:Win32/Ymacco.AACB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AACB virus can do?

  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Anomalous binary characteristics

Related domains:

guLJbikZmPNFDYdpNNPeSiH.guLJbikZmPNFDYdpNNPeSiH

How to determine Program:Win32/Ymacco.AACB?


File Info:

crc32: 11EEB2C2
md5: afe2eeb9c39fe0aaf3b98b1a570fd77c
name: AFE2EEB9C39FE0AAF3B98B1A570FD77C.mlw
sha1: ca42099bfeafd1a5c79180e0b406679eb5cae47d
sha256: cb751923695b52f799d7c20ca696069059187258021c9d8f8035e83180e8087d
sha512: 0a15dc447ab97a2129c3d4fddac9b1f6473e5108275053961baf0f4a36a78b50583ee675a1753a300ac9a90cf01447353ca69bba845aa7a78294b1e381969243
ssdeep: 49152:t5+hFlevtNUzY7WawmPzyxMAqpDHd5h419Pu0hO/k5:t5aFlevtw9uzCMdBf4xVhOY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Qwadebavr Dwdqodhukb. Vpd Payljq Fecbueye.
InternalName: Whogkbw
FileVersion: 7.57.4058.50476 (jjxshez_hpt.275249-1610)
CompanyName: Qwadebavr Dwdqodhukb
ProductName: Dcsyflmb Eyrhsdfg
ProductVersion: 7.57.4058.50476
FileDescription: Ujp92 Lrdcdbc Pripaecvoq
OriginalFilename: JSQWQZH.EXE .RAM
Translation: 0x0409 0x04b0

Program:Win32/Ymacco.AACB also known as:

CAT-QuickHealProgram.Wacapew
McAfeeArtemis!AFE2EEB9C39F
VIPREWin32.Malware!Drop
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.Agent.Wokba.A
K7GWTrojan ( 0057847f1 )
K7AntiVirusTrojan ( 0057847f1 )
ArcabitTrojan.Agent.Wokba.A
CyrenW32/Trojan.DBPP-3782
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 90)
AlibabaPacked:Win32/Redcap.93c9c7b8
MicroWorld-eScanTrojan.Agent.Wokba.A
RisingTrojan.HiddenRun/SFX!1.D2BC (CLASSIC)
Ad-AwareTrojan.Agent.Wokba.A
SophosGeneric PUA MK (PUA)
F-SecureTrojan.TR/Redcap.vavtd
DrWebBAT.Drop.2723
McAfee-GW-EditionArtemis!PUP
FireEyeGeneric.mg.afe2eeb9c39fe0aa
EmsisoftTrojan.Agent.Wokba.A (B)
AviraTR/Redcap.vavtd
KingsoftWin32.Troj.Generic.a.(kcloud)
GridinsoftTrojan.Win32.Packed.vb
MicrosoftProgram:Win32/Ymacco.AACB
GDataTrojan.Agent.Wokba.A
AhnLab-V3Dropper/Win32.Agent.C4347291
ALYacTrojan.Agent.Wokba.A
MalwarebytesTrojan.MalPack
PandaTrj/Agent.FUM
ESET-NOD32a variant of Win32/Packed.7zip.A suspicious
MAXmalware (ai score=85)
eGambitPE.Heur.InvalidSig
FortinetW32/7Zip.N!tr
WebrootW32.Trojan.Gen
Qihoo-360Win32/Heur.Generic.HyoDevkA

How to remove Program:Win32/Ymacco.AACB?

Program:Win32/Ymacco.AACB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment