Malware

Program:Win32/Ymacco.AACE removal guide

Malware Removal

The Program:Win32/Ymacco.AACE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AACE virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Installs a browser addon or extension
  • Attempts to modify Internet Explorer’s start page
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to modify desktop wallpaper
  • Network activity detected but not expressed in API logs
  • Attempts to modify browser security settings
  • Attempts to disable browser security warnings
  • Attempts to disable System Restore
  • Attempts to disable Windows Error Reporting
  • Attempts to disable Windows Auto Updates
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine Program:Win32/Ymacco.AACE?


File Info:

crc32: 3914E569
md5: 5e7f9864ba0c346137fe773fa484d7c4
name: 5E7F9864BA0C346137FE773FA484D7C4.mlw
sha1: b66ef0ca657df920e0af72b6d64174fad217d9c3
sha256: ce95932f9973fc373a6a58608e50d637ca753baa2333559689de7f397f52fbe4
sha512: 6c796ab4805aeb447ab71eda7f00fca8c02980205200978cb2a13e325650a0babb408d985372b6b4fd79cc5247bc27e32877d068b87d43d5cdff7f0e06cf4c38
ssdeep: 3072:Yt9opltkqljDcsDXiOzg02IwL85nPwgmL3kvVr/qe0jTHZeA8Q+w:Y9o7tHiKg02IwLgnIgiqaZ/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 x41ax43ex440x43fx43ex440x430x446x438x44f x41cx430x439x43ax440x43ex441x43ex444x442. x412x441x435 x43fx440x430x432x430 x437x430x449x438x449x435x43dx44b.
InternalName: REGEDIT
FileVersion: 5.1.2600.5512 (xpsp.080413-2111)
CompanyName: x41ax43ex440x43fx43ex440x430x446x438x44f x41cx430x439x43ax440x43ex441x43ex444x442
ProductName: x41ex43fx435x440x430x446x438x43ex43dx43dx430x44f x441x438x441x442x435x43cx430 Microsoftxae Windowsxae
ProductVersion: 5.1.2600.5512
FileDescription: x420x435x434x430x43ax442x43ex440 x440x435x435x441x442x440x430
OriginalFilename: REGEDIT.EXE
Translation: 0x0419 0x04b0

Program:Win32/Ymacco.AACE also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.FakeAV.19960
ALYacTrojan.RansomKD.6202257
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Blocker.c8b7fde3
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.4ba0c3
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Ransomkd-6990791-0
KasperskyTrojan-Ransom.Win32.Blocker.khyj
BitDefenderTrojan.RansomKD.6202257
NANO-AntivirusTrojan.Win32.Blocker.etjcqy
MicroWorld-eScanTrojan.RansomKD.6202257
TencentWin32.Trojan.Bp-startpage.Nlob
Ad-AwareTrojan.RansomKD.6202257
SophosGeneric PUA LG (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeTrojan.RansomKD.6202257
EmsisoftTrojan.RansomKD.6202257 (B)
AviraTR/Blocker.xslwr
MicrosoftProgram:Win32/Ymacco.AACE
GDataTrojan.RansomKD.6202257
AhnLab-V3Trojan/Win32.Blocker.C2345391
McAfeeArtemis!5E7F9864BA0C
MAXmalware (ai score=100)
VBA32Hoax.Blocker
PandaTrj/CI.A
FortinetW32/Blocker.KHYJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASScA

How to remove Program:Win32/Ymacco.AACE?

Program:Win32/Ymacco.AACE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment