Trojan

Trojan:Win32/Ymacco.AB09 malicious file

Malware Removal

The Trojan:Win32/Ymacco.AB09 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AB09 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Interacts with known DarkComet registry keys

How to determine Trojan:Win32/Ymacco.AB09?


File Info:

crc32: 7C6016B5
md5: 7919e0697b62ac0ea9c05c1abf534d46
name: 7919E0697B62AC0EA9C05C1ABF534D46.mlw
sha1: 3ba09b2b96745ad1956bc0e4445a02782787695f
sha256: 097885a32f5ab8b8faf4cc42a1b80f2fe80d5ddd9588bd1d79ea0b38909ae20b
sha512: 2ef33f5f8e6f4c4e2317ce8fc28945fe6b3bbd806905d40a6fb64c2daafab64f785ca71f51e1828d64e5cd4098b6a3bd1782c06e8bcb6f4f5bbd200205565315
ssdeep: 24576:sc3mDvjBxYOt7X9T2YmfLhls+zsQF5x6ie1YJkf:0DvjrYkNjmf/Fo454qJkf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.00.2900.2180
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE
Translation: 0x0409 0x04b0

Trojan:Win32/Ymacco.AB09 also known as:

K7AntiVirusTrojan ( 004d8efa1 )
Elasticmalicious (high confidence)
DrWebBackDoor.Bladabindi.10390
CynetMalicious (score: 100)
ALYacGen:Heur.Crifi.2
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004d8efa1 )
Cybereasonmalicious.97b62a
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Injector.COFG
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Dropper.DarkComet-6305705-0
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Heur.Crifi.2
NANO-AntivirusTrojan.Win32.Inject.dzetqz
MicroWorld-eScanGen:Heur.Crifi.2
Ad-AwareGen:Heur.Crifi.2
SophosML/PE-A + Troj/MDrop-GWI
ComodoMalware@#1ewiv4v85e50f
BitDefenderThetaAI:Packer.D1135D5F23
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericR-FKT!EF45336EE2E4
FireEyeGen:Heur.Crifi.2
EmsisoftGen:Heur.Crifi.2 (B)
JiangminTrojan.Yakes.efa
AviraHEUR/AGEN.1137692
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.160620E
KingsoftWin32.Troj.Generic.v.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AB09
SUPERAntiSpywareRansom.CryptoWall/Variant
GDataGen:Heur.Crifi.2
McAfeeArtemis!7919E0697B62
MAXmalware (ai score=85)
VBA32Trojan.Yakes
MalwarebytesRansom.CryptoWall
PandaGeneric Suspicious
RisingTrojan.Generic@ML.81 (RDML:hFTqgol/98WXyilCAO+HNg)
YandexTrojan.Yakes!5ApN7szXmr4
FortinetW32/Injector.COFG!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove Trojan:Win32/Ymacco.AB09?

Trojan:Win32/Ymacco.AB09 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment