Trojan

Trojan:Win32/Ymacco.AADA removal instruction

Malware Removal

The Trojan:Win32/Ymacco.AADA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AADA virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
rb3.ftnt.io

How to determine Trojan:Win32/Ymacco.AADA?


File Info:

crc32: EDFE7EA0
md5: dd672b509ea30af0fcb04bcb10f8defa
name: fsa_downloader_60a8d7.exe
sha1: 17a7b4d4dc09cad03233bae4583bccd362b1ae55
sha256: dab3e356ae57aca4560057b3a25c3ef050f26de39ea8a293fe2de0e52a60a8d7
sha512: 6b2feddcfc67ecb2faba696c779285e01fc3eeec12a57ffb35ba3863767472adcc4a6f5b4a8aa3a2f2a2dbf117d526d817ecb5931e55463c90b07603437b018b
ssdeep: 48:odTxwOZv1wOZGZdPkwOW1wAPFsXEJfmbJhr5BPr:oJxwOZv1wOZGZdPkwOW1wAPF+OfmdB5
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AADA also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.TestSample.B
FireEyeGeneric.mg.dd672b509ea30af0
CAT-QuickHealTrojan.Wacatac
Qihoo-360Generic/HEUR/QVM20.1.9963.Malware.Gen
McAfeeGenericRXHA-OK!DD672B509EA3
CylanceUnsafe
VIPRETrojan-Downloader.Win32.Small!cobra (v)
SangforMalware
K7AntiVirusTrojan ( 005692221 )
BitDefenderTrojan.TestSample.B
K7GWTrojan ( 005692221 )
Cybereasonmalicious.09ea30
Invinceaheuristic
F-ProtW32/Downloader-Sml!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
GDataTrojan.TestSample.B
AlibabaTrojan:Application/Generic.850a05cb
AegisLabTrojan.Win32.TestSample.4!c
Endgamemalicious (high confidence)
SophosTroj/AutoG-ER
ComodoTrojWare.Win32.Agent.SFSC@8t0i0z
F-SecureTrojan.TR/Crypt.XPACK.Gen
TrendMicroTROJ_GEN.R002C0PGF20
EmsisoftTrojan.TestSample.B (B)
IkarusTrojan.TestSample
CyrenW32/Downloader-Sml!Eldorado
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.SGeneric
ArcabitTrojan.TestSample.B
MicrosoftTrojan:Win32/Ymacco.AADA
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C1472977
Acronissuspicious
VBA32suspected of Trojan.Downloader.gen.h
Ad-AwareTrojan.TestSample.B
MalwarebytesRiskWare.TestSample
TrendMicro-HouseCallTROJ_GEN.R002C0PGF20
RisingTrojan.Ymacco!8.11BE1 (RDMK:cmRtazpsVFcWAEsMsFdCJ/S5jP/z)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
BitDefenderThetaGen:NN.ZexaF.34138.amW@a4Uqt!o
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/Ymacco.AADA?

Trojan:Win32/Ymacco.AADA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment