Trojan

Trojan:Win32/Ymacco.AAAF removal tips

Malware Removal

The Trojan:Win32/Ymacco.AAAF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AAAF virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

rb3.ftnt.io

How to determine Trojan:Win32/Ymacco.AAAF?


File Info:

crc32: B7A9174C
md5: bf15c6c232ebefef1fa26f37c8ea1770
name: fsa_downloader_41aae0.exe
sha1: a5798283f985bd226f622165267681acdf761cd5
sha256: afa32dad8c91e7244c8f7b095c75ad1b5fbc61bb09dd0beec934aff43741aae0
sha512: 865d146a479f00c83137e2bfee26a30c7c0097232b44469854c8b7b760c4e9656a496cfa64c2f6ac584a19d42683b50131e105fc22d560a646a76c8840151a51
ssdeep: 48:odTxwOZv1wOZGZdPkwOW1wAPFsXEJfmbJITTTTTTTTTTTTTTTTTTTTTTTTTTTTT:oJxwOZv1wOZGZdPkwOW1wAPF+Ofmd35
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AAAF also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.TestSample.B
FireEyeGeneric.mg.bf15c6c232ebefef
McAfeeGenericRXHA-OK!BF15C6C232EB
CylanceUnsafe
AegisLabTrojan.Win32.TestSample.4!c
SangforMalware
K7AntiVirusTrojan ( 005692221 )
BitDefenderTrojan.TestSample.B
K7GWTrojan ( 005692221 )
Cybereasonmalicious.232ebe
TrendMicroTROJ_GEN.R015C0PFB20
F-ProtW32/Downloader-Sml!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
AlibabaTrojan:Application/Generic.3845ee45
ViRobotTrojan.Win32.Z.Testsample.4096.NP
Endgamemalicious (high confidence)
EmsisoftTrojan.TestSample.B (B)
ComodoTrojWare.Win32.Agent.SFSC@8t0i0z
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPRETrojan-Downloader.Win32.Small!cobra (v)
Invinceaheuristic
SophosTroj/AutoG-ER
IkarusTrojan.TestSample
CyrenW32/Downloader-Sml!Eldorado
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.SGeneric
ArcabitTrojan.TestSample.B
MicrosoftTrojan:Win32/Ymacco.AAAF
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C1472977
Acronissuspicious
VBA32suspected of Trojan.Downloader.gen.h
ALYacTrojan.TestSample.B
Ad-AwareTrojan.TestSample.B
MalwarebytesRiskWare.TestSample
TrendMicro-HouseCallTROJ_GEN.R015C0PFB20
RisingTrojan.Ymacco!8.11BE1 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
GDataTrojan.TestSample.B
BitDefenderThetaGen:NN.ZexaF.34138.amW@a4Uqt!o
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM20.1.DB9B.Malware.Gen

How to remove Trojan:Win32/Ymacco.AAAF?

Trojan:Win32/Ymacco.AAAF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment