Malware

PWS:Win32/Ymacco.AA50 malicious file

Malware Removal

The PWS:Win32/Ymacco.AA50 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Ymacco.AA50 virus can do?

  • Executable code extraction
  • Anomalous binary characteristics

How to determine PWS:Win32/Ymacco.AA50?


File Info:

crc32: 1D714E7A
md5: ad0c93b574bb947cff15483eda82811e
name: AD0C93B574BB947CFF15483EDA82811E.mlw
sha1: ad379c5a86bf646c4a079e737a364ab352107e5b
sha256: bcaac39113bd17158fe86a77328f97e9c3fa14860c9c4449a8ae0768c85243f4
sha512: b31231362967089a28f24f84dfd185fdb9e2fc940eabd112beff03968993f9d7a820adc1db83a6775a3473c8ff2fad8d067c7ca16b4a7e7c57337450bedfc109
ssdeep: 6144:zvEN2U+T6i5LirrllHy4HUcMQY6ZOaoi7ru0qFkBYDoogRI30z0noojfIVAdayb1:zENN+T5xYrllrU7QY65oiHuhGYDoogR0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Win
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Win
ProductVersion: 1.00
OriginalFilename: Win.exe

PWS:Win32/Ymacco.AA50 also known as:

BkavW32.VBOverlayD.PE
K7AntiVirusTrojan ( 0040f0591 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.54687
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mofksys.A
ALYacTrojan.Generic.6753864
CylanceUnsafe
ZillyaTrojan.Swisyn.Win32.32298
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0040f0591 )
Cybereasonmalicious.574bb9
BaiduWin32.Trojan.VB.at
CyrenW32/VB.AD.gen!Eldorado
SymantecW32.Gosys
ESET-NOD32Win32/VB.OSK
ZonerTrojan.Win32.47063
APEXMalicious
AvastWin32:VB-AJKP [Trj]
ClamAVWin.Trojan.VBGeneric-6735885-0
KasperskyTrojan.Win32.Swisyn.bner
BitDefenderTrojan.Generic.6753864
NANO-AntivirusTrojan.Win32.Swisyn.efyboj
MicroWorld-eScanTrojan.Generic.6753864
TencentTrojan.Win32.Swisyn.b
Ad-AwareTrojan.Generic.6753864
SophosMal/Generic-R + Troj/VB-JVT
ComodoTrojWare.Win32.VB.OSKB@4pc2ok
BitDefenderThetaAI:Packer.4726EE0B20
VIPRETrojan-PWS.Win32.VB.cu (v)
TrendMicroPE_MOFKSYS.A
McAfee-GW-EditionBehavesLike.Win32.Swisyn.fm
FireEyeGeneric.mg.ad0c93b574bb947c
EmsisoftTrojan.Generic.6753864 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Swisyn.rmj
AviraTR/Dropper.Gen
MicrosoftPWS:Win32/Ymacco.AA50
GridinsoftTrojan.Win32.Agent.vb!s1
AegisLabTrojan.Win32.Swisyn.lmsx
GDataTrojan.Generic.6753864
AhnLab-V3Trojan/Win32.Swisyn.R1452
Acronissuspicious
McAfeeW32/Swisyn.ag
MAXmalware (ai score=89)
VBA32MAS.Trojan.VB.01049
MalwarebytesPioneer.Virus.FileInfector.DDS
PandaGeneric Malware
TrendMicro-HouseCallPE_MOFKSYS.A
RisingTrojan.QOT!1.6519 (CLOUD)
YandexTrojan.GenAsa!dm5qTke+fEg
IkarusTrojan-Spy.MSIL.Omaneat
MaxSecureTrojan.Swisyn.BNER
FortinetW32/VB.QOT!tr
AVGWin32:VB-AJKP [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM03.0.87F7.Malware.Gen

How to remove PWS:Win32/Ymacco.AA50?

PWS:Win32/Ymacco.AA50 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment