Trojan

About “Trojan:Win32/Ymacco.AB08” infection

Malware Removal

The Trojan:Win32/Ymacco.AB08 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AB08 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.zcjczj.cn
config.zcjczj.cn
con2.zcjczj.cn
pv.sohu.com
ip.ws.126.net
info.zcjczj.cn
media.zcjczj.cn
pm.myapp.com
ocsp.dcocsp.cn

How to determine Trojan:Win32/Ymacco.AB08?


File Info:

crc32: 8836B204
md5: 03417211431d04bce8d68d62c0ca2543
name: evapicturesetup-4858.exe
sha1: 22f5b9c372a40a04102d3f05c8281dc19f31a4d7
sha256: 086631f9d316f0e544410f3c074ee6792cd8b6b00cf15fb98ddcc154eda53589
sha512: 998b6801c4b76059c92e30850bb1d360466fa6917572702f2cca08ec4cdf35602d61b74ca8c3f13bdffeab8c34c66d142bc09692f1171ea5e6ebeaa212c84b69
ssdeep: 98304:kdJcUQLUGrupm8ECqy8iOTTT1RJUOCavV8OzLqhf:4PGZKm8EnfT1RJUOBvXnqhf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Setup Engine Copyright xa9 2004-2018 Indigo Rose Corporation
InternalName: suf_launch
FileVersion: 9.5.2.0
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
Comments: Created with Setup Factory
ProductName: Setup Factory Runtime
ProductVersion: 9.5.2.0
FileDescription: Setup Application
OriginalFilename: suf_launch.exe
Translation: 0x0409 0x04e4

Trojan:Win32/Ymacco.AB08 also known as:

MicroWorld-eScanTrojan.GenericKD.34754954
FireEyeTrojan.GenericKD.34754954
CAT-QuickHealTrojanDownloader.Chindo
McAfeeArtemis!03417211431D
CylanceUnsafe
ZillyaDownloader.Chindo.Win32.1252
SangforMalware
K7AntiVirusTrojan-Downloader ( 0055f6a61 )
K7GWTrojan-Downloader ( 0055f6a61 )
Cybereasonmalicious.1431d0
InvinceaMal/Generic-S
CyrenW32/Trojan.ZLAS-2621
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Malware.Generic-7589901-0
KasperskyHEUR:Trojan-Downloader.Win32.Chindo.vho
BitDefenderTrojan.GenericKD.34754954
Paloaltogeneric.ml
Ad-AwareTrojan.GenericKD.34754954
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.CHINDO.USMANJC20
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.34754954 (B)
GDataTrojan.GenericKD.34754954
AviraHEUR/AGEN.1137534
ArcabitTrojan.Generic.D212518A
AegisLabTrojan.Win32.Chindo.a!c
ZoneAlarmHEUR:Trojan-Downloader.Win32.Chindo.vho
MicrosoftTrojan:Win32/Ymacco.AB08
ALYacTrojan.GenericKD.43957488
MAXmalware (ai score=81)
VBA32BScope.Trojan.Ekstak
ESET-NOD32multiple detections
TrendMicro-HouseCallTrojan.Win32.CHINDO.USMANJC20
RisingAdware.Agent!1.C1FF (CLASSIC)
IkarusTrojan.Indiloadz
FortinetW32/Ursu.789031!tr
MaxSecureTrojan.Malware.74710104.susgen
AVGWin32:DropperX-gen [Drp]
Qihoo-360Generic/Trojan.585

How to remove Trojan:Win32/Ymacco.AB08?

Trojan:Win32/Ymacco.AB08 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment