Trojan

Trojan:Win32/Ymacco.AAA8 removal guide

Malware Removal

The Trojan:Win32/Ymacco.AAA8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AAA8 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Anomalous binary characteristics

Related domains:

rb3.ftnt.io

How to determine Trojan:Win32/Ymacco.AAA8?


File Info:

crc32: 7EF46ECD
md5: 4fa9417d1df54770ec6be211d837cfe5
name: fsa_downloader_4af352.exe
sha1: fab2b5ffc032264421ead5acf4ab2e77b306652e
sha256: ca2d222a45c1381cfeeec029a80879f6a1204a56a066290d735cf653f74af352
sha512: fa7e518ad554be18d6553b4302bfd63d4dde8cbaf5ea415b8165a65611869e7e61bea3ceccc4d3deb625cec9db50d00509c3ee8d08c42ee0b3fd2e2ac1182395
ssdeep: 48:odTxwOZv1wOZGZdPkwOW1wAPFsXEJfmbJur5BPr:oJxwOZv1wOZGZdPkwOW1wAPF+Ofmd45
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AAA8 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.TestSample.B
FireEyeGeneric.mg.4fa9417d1df54770
CAT-QuickHealTrojan.Wacatac
ALYacTrojan.TestSample.B
CylanceUnsafe
VIPRETrojan-Downloader.Win32.Small!cobra (v)
AegisLabTrojan.Win32.TestSample.4!c
SangforMalware
K7AntiVirusTrojan ( 005692221 )
BitDefenderTrojan.TestSample.B
K7GWTrojan ( 005692221 )
Cybereasonmalicious.d1df54
TrendMicroTROJ_GEN.R015C0PFD20
F-ProtW32/Downloader-Sml!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.TestSample.B
AlibabaTrojan:Application/Generic.973faef9
ViRobotTrojan.Win32.Z.Testsample.4096.OC
Ad-AwareTrojan.TestSample.B
EmsisoftTrojan.TestSample.B (B)
ComodoTrojWare.Win32.Agent.SFSC@8t0i0z
F-SecureTrojan.TR/Crypt.XPACK.Gen
Invinceaheuristic
SophosTroj/AutoG-ER
IkarusTrojan.TestSample
CyrenW32/Downloader-Sml!Eldorado
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.SGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.TestSample.B
MicrosoftTrojan:Win32/Ymacco.AAA8
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C1472977
Acronissuspicious
McAfeeGenericRXHA-OK!4FA9417D1DF5
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesRiskWare.TestSample
TrendMicro-HouseCallTROJ_GEN.R015C0PFD20
RisingTrojan.Ymacco!8.11BE1 (CLOUD)
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.74274700.susgen
BitDefenderThetaGen:NN.ZexaF.34130.amW@a4Uqt!o
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM20.1.F40C.Malware.Gen

How to remove Trojan:Win32/Ymacco.AAA8?

Trojan:Win32/Ymacco.AAA8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment