Trojan

Trojan:Win32/Ymacco.AAF7 removal instruction

Malware Removal

The Trojan:Win32/Ymacco.AAF7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AAF7 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

rb3.ftnt.io

How to determine Trojan:Win32/Ymacco.AAF7?


File Info:

crc32: 6173F56F
md5: 1d8c1cabba6f5cb05a6eeb4e1bf24669
name: fsa_downloader_3de02c.exe
sha1: 29ba3e113f139bf0dbc35eec37f59dc7a042ff23
sha256: f7fca8e5940648338cdbb8dadc36305d7bb37d08c0990a5288538f658a3de02c
sha512: 242f747287d7e488c820922f0feecfe856cc487397ecb552907006ede569b0487247bc518f3c84e2209f8c298bf1a27b45d6eb636b624d13fe91197506672f66
ssdeep: 48:odTxwOZv1wOZGZdPkwOW1wAPFsXEJfmbJTr5BPr:oJxwOZv1wOZGZdPkwOW1wAPF+Ofmd35
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AAF7 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.TestSample.B
FireEyeGeneric.mg.1d8c1cabba6f5cb0
McAfeeGenericRXHA-OK!1D8C1CABBA6F
CylanceUnsafe
AegisLabTrojan.Win32.TestSample.4!c
SangforMalware
K7AntiVirusTrojan ( 005692221 )
BitDefenderTrojan.TestSample.B
K7GWTrojan ( 005692221 )
Cybereasonmalicious.bba6f5
Invinceaheuristic
F-ProtW32/Downloader-Sml!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
GDataTrojan.TestSample.B
AlibabaTrojan:Application/Generic.25854c7b
RisingTrojan.Ymacco!8.11BE1 (RDMK:cmRtazpsVFcWAEsMsFdCJ/S5jP/z)
Ad-AwareTrojan.TestSample.B
SophosTroj/AutoG-ER
ComodoTrojWare.Win32.Agent.SFSC@8t0i0z
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPRETrojan-Downloader.Win32.Small!cobra (v)
TrendMicroTROJ_GEN.R015C0PG320
MaxSecureTrojan.Malware.300983.susgen
EmsisoftTrojan.TestSample.B (B)
IkarusTrojan.TestSample
CyrenW32/Downloader-Sml!Eldorado
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.SGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.TestSample.B
MicrosoftTrojan:Win32/Ymacco.AAF7
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C1472977
Acronissuspicious
ALYacTrojan.TestSample.B
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesRiskWare.TestSample
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R015C0PG320
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
BitDefenderThetaGen:NN.ZexaF.34138.amW@a4Uqt!o
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.fc2

How to remove Trojan:Win32/Ymacco.AAF7?

Trojan:Win32/Ymacco.AAF7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment