Malware

How to remove “Program:Win32/Ymacco.AAD0”?

Malware Removal

The Program:Win32/Ymacco.AAD0 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AAD0 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
d19k2w78yakd9g.cloudfront.net
s.symcd.com
ocsp.digicert.com

How to determine Program:Win32/Ymacco.AAD0?


File Info:

crc32: 0D07A23E
md5: 40189104ab0c694700ff216147e1b718
name: 40189104AB0C694700FF216147E1B718.mlw
sha1: 9d3dd676ffe71b61851a52b16139c551cd41e42a
sha256: d0077789822f74742ba6a3d09892dc83b2ab1d52538056323aadb2bda6c7474d
sha512: b57793c4c6bcf577fb761d8112990805e05f7f4689c54422324b3e8addb3482d09120004cde5294300d22e7a62d49ba9ae815889b83081d4068be69b21220103
ssdeep: 1536:KpgpHzb9dZVX9fHMvG0D3XJZ4Romu/d4iiIGlf2mBi3nB:IgXdZt9P6D3XJZ45ui7OhnB
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Program:Win32/Ymacco.AAD0 also known as:

CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BaiduNSIS.Trojan-Downloader.Agent.cw
CyrenW32/Trojan.BQUM-0735
SymantecTrojan.Gen.MBT
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.Neoreklami.gen
AlibabaAdWare:Win32/Neoreklami.c34cb115
ViRobotTrojan.Win32.Z.Neoreklami.76005
DrWebTrojan.DownLoad4.14213
TrendMicroTROJ_GEN.R002C0PAT21
McAfee-GW-EditionBehavesLike.Win32.Dropper.lc
SophosGeneric Reputation PUA (PUA)
MicrosoftProgram:Win32/Ymacco.AAD0
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Neoreklami.gen
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4305256
McAfeeArtemis!40189104AB0C
VBA32suspected of Trojan.Downloader.gen.s
MalwarebytesAdware.Dropper
TrendMicro-HouseCallTROJ_GEN.R002C0PAT21
IkarusTrojan-Downloader.NSIS.Adload
FortinetAdware/Neoreklami
Qihoo-360Win32/Virus.Adware.d36

How to remove Program:Win32/Ymacco.AAD0?

Program:Win32/Ymacco.AAD0 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment