Trojan

Trojan:Win32/Ymacco.AA85 removal tips

Malware Removal

The Trojan:Win32/Ymacco.AA85 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA85 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
rb3.ftnt.io
a.tomx.xyz

How to determine Trojan:Win32/Ymacco.AA85?


File Info:

crc32: AE474174
md5: 3b24bfb53ad926b214aa7053a9149b26
name: fsa_downloader_922fb7.exe
sha1: 6a3558e5f8683b0328833bd8f01628b61a1fbc2b
sha256: 8547dd60a6fe05439d8d9762f513345bd6d3cbd54f87df2e1eb4992366922fb7
sha512: 3d288b79834ab59cccba9132dddac34b975afbd617cee9f2533b0360dbb4334885cd580191a0240880f9f6cf81ddd18e32714af1d5e3c24a3d1838258c3bce8d
ssdeep: 96:oJxwOZv1wOZGZdPkwOW1wAPF+OfmdIeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee:oJxwOZv1wOZGZdPkwOW1wAPF+OudO
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AA85 also known as:

BkavW32.AIDetectVM.malware2
CynetMalicious (score: 100)
FireEyeGeneric.mg.3b24bfb53ad926b2
McAfeeGenericRXHA-OK!3B24BFB53AD9
CylanceUnsafe
AegisLabTrojan.Win32.TestSample.4!c
SangforMalware
K7AntiVirusTrojan ( 005692221 )
BitDefenderTrojan.TestSample.B
K7GWTrojan ( 005692221 )
Cybereasonmalicious.53ad92
TrendMicroTROJ_GEN.R015C0PFR20
F-ProtW32/Downloader-Sml!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
GDataTrojan.TestSample.B
AlibabaTrojan:Application/Generic.3593a912
NANO-AntivirusTrojan.Win32.TestSample.hoaiea
MicroWorld-eScanTrojan.TestSample.B
Endgamemalicious (high confidence)
SophosTroj/AutoG-ER
ComodoTrojWare.Win32.Agent.SFSC@8t0i0z
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPRETrojan-Downloader.Win32.Small!cobra (v)
Invinceaheuristic
EmsisoftTrojan.TestSample.B (B)
IkarusTrojan.TestSample
CyrenW32/Downloader-Sml!Eldorado
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.XPACK.Gen
WebrootW32.Trojan.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.SGeneric
ArcabitTrojan.TestSample.B
MicrosoftTrojan:Win32/Ymacco.AA85
AhnLab-V3Malware/Gen.Generic.C1472977
Acronissuspicious
VBA32suspected of Trojan.Downloader.gen.h
ALYacTrojan.TestSample.B
Ad-AwareTrojan.TestSample.B
MalwarebytesRiskWare.TestSample
TrendMicro-HouseCallTROJ_GEN.R015C0PFR20
RisingTrojan.Ymacco!8.11BE1 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
BitDefenderThetaGen:NN.ZexaF.34138.amW@a4Uqt!o
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM20.1.460E.Malware.Gen

How to remove Trojan:Win32/Ymacco.AA85?

Trojan:Win32/Ymacco.AA85 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment