Trojan

Trojan:Win32/Ymacco.AA1A removal

Malware Removal

The Trojan:Win32/Ymacco.AA1A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA1A virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
rb3.ftnt.io

How to determine Trojan:Win32/Ymacco.AA1A?


File Info:

crc32: D6253FAC
md5: a0e631a52440f6d522c65bcecc097e32
name: fsa_downloader_1d68e5.exe
sha1: 60e2fae9d06595acdaae9e216d88415d92d60ce1
sha256: 1a49dca91e0cc3bdba1731e8104654f8f97fc988a46d80c74d215a0ab71d68e5
sha512: 07a1d771650b42ef45d4b382dc83c25fa109225e19f13354fdd0b5847c5f1378e7089533bcfe089622f75047e3ab1de2c85ea9a6f31bac94efbb96fa10137e5b
ssdeep: 96:oJxwOZv1wOZGZdPkwOW1wAPF+Ofmdjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjjj:oJxwOZv1wOZGZdPkwOW1wAPF+Oudp
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AA1A also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.TestSample.B
FireEyeGeneric.mg.a0e631a52440f6d5
CAT-QuickHealTrojan.Wacatac
McAfeeGenericRXHA-OK!A0E631A52440
MalwarebytesRiskWare.TestSample
VIPRETrojan-Downloader.Win32.Small!cobra (v)
SangforMalware
K7AntiVirusTrojan ( 005692221 )
BitDefenderTrojan.TestSample.B
K7GWTrojan ( 005692221 )
Cybereasonmalicious.52440f
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34138.amW@a4Uqt!o
CyrenW32/Downloader-Sml!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
GDataTrojan.TestSample.B
AlibabaTrojan:Application/Generic.09ab6bf9
AegisLabTrojan.Win32.TestSample.4!c
Endgamemalicious (high confidence)
SophosTroj/AutoG-ER
ComodoTrojWare.Win32.Agent.SFSC@8t0i0z
F-SecureTrojan.TR/Crypt.XPACK.Gen
TrendMicroTROJ_GEN.R002C0PFI20
EmsisoftTrojan.TestSample.B (B)
IkarusTrojan.TestSample
F-ProtW32/Downloader-Sml!Eldorado
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.SGeneric
ArcabitTrojan.TestSample.B
MicrosoftTrojan:Win32/Ymacco.AA1A
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C1472977
Acronissuspicious
VBA32suspected of Trojan.Downloader.gen.h
MAXmalware (ai score=87)
Ad-AwareTrojan.TestSample.B
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PFI20
RisingTrojan.Ymacco!8.11BE1 (RDMK:cmRtazpsVFcWAEsMsFdCJ/S5jP/z)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.fc2

How to remove Trojan:Win32/Ymacco.AA1A?

Trojan:Win32/Ymacco.AA1A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment