Trojan

Trojan:Win32/Ymacco.AAB0 removal instruction

Malware Removal

The Trojan:Win32/Ymacco.AAB0 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AAB0 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

rb3.ftnt.io

How to determine Trojan:Win32/Ymacco.AAB0?


File Info:

crc32: BDF58C77
md5: 05bc5e5ee012e0dd1ddb9b1c3412459c
name: fsa_downloader_856940.exe
sha1: 35fb2e92a60ee674bc0b46489ed52d26718d66dc
sha256: b0df5ca15c99d7c7caeac1f7bea90a65c442e49d64f6af8dbf631efb69856940
sha512: cba80c1a9d8af7fbdc1f978d2e16ec4eb4656f7f6b37097a9fc56a8e6d7700403bb59c1ef380af43aed23bc09f0e5ff198fdb29c0078e94669e3dc1fe31397b6
ssdeep: 96:oJxwOZv1wOZGZdPkwOW1wAPF+Ofmdb000000000000000000000000000000000:oJxwOZv1wOZGZdPkwOW1wAPF+Oudb00
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AAB0 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.TestSample.B
FireEyeGeneric.mg.05bc5e5ee012e0dd
ALYacTrojan.TestSample.B
MalwarebytesRiskWare.TestSample
VIPRETrojan-Downloader.Win32.Small!cobra (v)
AegisLabTrojan.Win32.TestSample.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderTrojan.TestSample.B
K7GWTrojan ( 005692221 )
K7AntiVirusTrojan ( 005692221 )
TrendMicroTROJ_GEN.R002C0PGN20
BitDefenderThetaGen:NN.ZexaF.34138.amW@a4Uqt!o
CyrenW32/Downloader-Sml!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
AlibabaTrojan:Application/Generic.ac9496a3
Ad-AwareTrojan.TestSample.B
ComodoTrojWare.Win32.Agent.SFSC@8t0i0z
F-SecureTrojan.TR/Crypt.XPACK.Gen
Invinceaheuristic
EmsisoftTrojan.TestSample.B (B)
IkarusTrojan.TestSample
GDataTrojan.TestSample.B
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/Ymacco.AAB0
Endgamemalicious (high confidence)
ArcabitTrojan.TestSample.B
AhnLab-V3Malware/Gen.Generic.C1472977
Acronissuspicious
McAfeeGenericRXHA-OK!05BC5E5EE012
MAXmalware (ai score=81)
VBA32suspected of Trojan.Downloader.gen.h
TrendMicro-HouseCallTROJ_GEN.R002C0PGN20
RisingTrojan.Ymacco!8.11BE1 (RDMK:cmRtazpsVFcWAEsMsFdCJ/S5jP/z)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
Qihoo-360Generic/HEUR/QVM20.1.C637.Malware.Gen
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/Ymacco.AAB0?

Trojan:Win32/Ymacco.AAB0 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment