Malware

Should I remove “Win32/ATM.AA”?

Malware Removal

The Win32/ATM.AA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/ATM.AA virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/ATM.AA?


File Info:

name: 4E7CF20EB0FEA42CEB96.mlw
path: /opt/CAPEv2/storage/binaries/37f7d301b35e2a9e5aee472a9956df91e2f25cf67f0aae4d798bb1867f08ff65
crc32: 985CEA88
md5: 4e7cf20eb0fea42ceb96f68bc0179e3e
sha1: 8ab9ab7a727d4a86376b96d462e8ef0221046ca1
sha256: 37f7d301b35e2a9e5aee472a9956df91e2f25cf67f0aae4d798bb1867f08ff65
sha512: 68425a10f37cff0d9489e0790f4f4a43086bd3c17de327f812e2a236e45024ce3dd9a459f555b97a92e66e512f304dbaaa432fccaf8d317de393f0e23644ee84
ssdeep: 192:PuO3a4d3+GGPcJ93PVZ8tjPIZDJQOZqbuclxt1+cFGP/pbq/doPU7R+4iD8i2C4g:Pug3+GGSagJklx9o/pbqloPUd+vgF
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10A82C68DAF056DF3EE1541B530F997BBCA39F265D84208E4FB80D31C6416826A37CAA5
sha3_384: b3ea15788c46fd7f274ccd2a8daaca7408be95e25cc125831c9c08f2317b3aebc76cf8efd73e627c3bf064ea6a3c3538
ep_bytes: 83ec1cc7042401000000ff1560714000
timestamp: 1971-05-15 13:40:48

Version Info:

0: [No Data]

Win32/ATM.AA also known as:

MicroWorld-eScanTrojan.GenericKD.38184044
FireEyeTrojan.GenericKD.38184044
ALYacTrojan.GenericKD.38184044
CylanceUnsafe
ZillyaTrojan.ATM.Win32.23
K7AntiVirusTrojan ( 005667f21 )
BitDefenderTrojan.GenericKD.38184044
K7GWTrojan ( 005667f21 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/ATM.AA
TrendMicro-HouseCallTROJ_GEN.R002H0CL421
KasperskyHEUR:Trojan.Win32.CessoATM.gen
ViRobotTrojan.Win32.Z.Atm.17920
RisingTrojan.Dispcash!1.C332 (CLASSIC)
Ad-AwareTrojan.GenericKD.38184044
SophosMal/Generic-S
DrWebTrojan.Siggen9.45393
McAfee-GW-EditionRDN/Generic.dx
EmsisoftTrojan.GenericKD.38184044 (B)
IkarusTrojan.Win32.Atm
JiangminTrojan.ATM.a
AviraTR/Banker.atm.A
Antiy-AVLTrojan/Generic.ASMalwS.3040589
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataTrojan.GenericKD.38184044
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.ATMRod.R336912
McAfeeRDN/Generic.dx
MAXmalware (ai score=89)
VBA32BScope.Trojan.ATM
TencentWin32.Trojan.Cessoatm.Pfts
FortinetW32/ATM.AA!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/ATM.AA?

Win32/ATM.AA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment