Malware

Program:Win32/Ymacco.AADA information

Malware Removal

The Program:Win32/Ymacco.AADA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Program:Win32/Ymacco.AADA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Program:Win32/Ymacco.AADA?


File Info:

crc32: A339548E
md5: fed8be994613fe231d37f362cf6f65e9
name: FED8BE994613FE231D37F362CF6F65E9.mlw
sha1: 15437be7ad95c9d199fe40031ae6f3e781574335
sha256: da815fd0dfdd0f958dcef1d55e6350a484064e17b60276a5212e983ca79bf1b1
sha512: 6c9ce44a7ec627b9d57d07b4ae4a82b8e7d5e24a3ae96f2ee7124e4d29c8c10a6098914d327cd9fe45753bf4b72b4ce7043a081d81d9b171ae0416ed27731be0
ssdeep: 49152:iKM/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb/rb:
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 360.cn Inc. All Rights Reserved.
InternalName: 360DeskAna.exe
FileVersion: 1, 0, 0, 1018
CompanyName: 360.cn
ProductName: 360????
ProductVersion: 1, 0, 0, 1018
FileDescription: 360???? ??????????
OriginalFilename: 360DeskAna.exe
Translation: 0x0804 0x04b0

Program:Win32/Ymacco.AADA also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.71897
FireEyeGeneric.mg.fed8be994613fe23
Qihoo-360HEUR/QVM39.1.F77B.Malware.Gen
McAfeeGenericRXMZ-SU!FED8BE994613
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 00574aa51 )
BitDefenderTrojan.GenericKDZ.71897
K7GWTrojan ( 00574aa51 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZedlaF.34700.d28@aODV4Wlj
CyrenW32/Kryptik.CSG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIGG
APEXMalicious
ClamAVWin.Trojan.Generic-9808189-0
KasperskyUDS:DangerousObject.Multi.Generic
AegisLabHacktool.Win32.Krap.lKMc
Ad-AwareTrojan.GenericKDZ.71897
EmsisoftTrojan.GenericKDZ.71897 (B)
F-SecureTrojan.TR/Crypt.Agent.xahux
DrWebTrojan.Inject4.6225
McAfee-GW-EditionBehavesLike.Win32.Dropper.vt
SophosML/PE-A + Mal/EncPk-APV
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.RTM.tc
AviraTR/Crypt.Agent.xahux
Antiy-AVLGrayWare/Win32.Kryptik.ehls
MicrosoftProgram:Win32/Ymacco.AADA
GridinsoftTrojan.Win32.Kryptik.oa!s11
ArcabitTrojan.Generic.D118D9
AhnLab-V3Malware/Win32.RL_Generic.R358128
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.GenericKDZ.71897
CynetMalicious (score: 100)
VBA32BScope.Backdoor.Vawtrak
MAXmalware (ai score=84)
RisingTrojan.Kryptik!1.CFFC (CLASSIC)
FortinetW32/Kryptik.HDNN!tr
AVGWin32:BankerX-gen [Trj]
PandaTrj/GdSda.A

How to remove Program:Win32/Ymacco.AADA?

Program:Win32/Ymacco.AADA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment