Malware

VirTool:Win32/Ymacco.AA1C information

Malware Removal

The VirTool:Win32/Ymacco.AA1C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:Win32/Ymacco.AA1C virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Pony malware
  • Exhibits possible ransomware file modification behavior
  • Collects information about installed applications
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics

How to determine VirTool:Win32/Ymacco.AA1C?


File Info:

crc32: 010E1CAB
md5: bab27b99ce7635dce2034e76ad50da53
name: upload_file
sha1: bd90ad25c9baaf59b154ef2b02d3920e859aca38
sha256: 1cb19bb516aee6eb9a4776685dc50facce9fb5c4dffad2fe7e900f2295708ce9
sha512: 40c1a4d889386506a62e37be7366ad98519579caaa35994de5536eeaa3529005b6fbc0f0d83ceec506686906e3ade0b1807e3b75a526fa8c9973d0b3190f036e
ssdeep: 6144:6CFNcE5fx1TYK4xkv/BugEm4QBsJ4xLykzi6lNCY:DNcE5fT54xkv/B34QBFukzi6lNR
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

VirTool:Win32/Ymacco.AA1C also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.2099
MicroWorld-eScanTrojan.Crypt.Delf.AL
ALYacTrojan.Crypt.Delf.AL
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056e25b1 )
BitDefenderTrojan.Crypt.Delf.AL
K7GWTrojan ( 0056e25b1 )
ArcabitTrojan.Crypt.Delf.AL
InvinceaMal/Generic-S
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EMZR
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Remcos-7839438-0
KasperskyHEUR:Trojan.Win32.Pincav.gen
AlibabaVirTool:Win32/Ymacco.bcc02c48
ViRobotTrojan.Win32.Z.Delfinject.287744
AegisLabTrojan.Win32.Pincav.4!c
AvastWin32:Inject-XW [Trj]
Ad-AwareTrojan.Crypt.Delf.AL
EmsisoftTrojan.Crypt.Delf.AL (B)
ComodoMalware@#1ssc8xinjwdtj
F-SecureTrojan.TR/Hijacker.Gen
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.DELF.THJOGBO
McAfee-GW-EditionBehavesLike.Win32.Injector.dc
FireEyeGeneric.mg.bab27b99ce7635dc
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
AviraTR/Hijacker.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Pincav
MicrosoftVirTool:Win32/Ymacco.AA1C
ZoneAlarmHEUR:Trojan.Win32.Pincav.gen
GDataWin32.Trojan.Buzus.C
CynetMalicious (score: 100)
McAfeeGenericRXKC-XL!BAB27B99CE76
VBA32BScope.Backdoor.Agent
MalwarebytesTrojan.Injector
TrendMicro-HouseCallTrojan.Win32.DELF.THJOGBO
RisingTrojan.Injector!8.C4 (TFE:4:jyPlqnfOVXS)
IkarusVirus.Win32.DelfInject
FortinetW32/Pincav.XL!tr
AVGWin32:Inject-XW [Trj]
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.959

How to remove VirTool:Win32/Ymacco.AA1C?

VirTool:Win32/Ymacco.AA1C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment