Trojan

Should I remove “Trojan:Win32/Ymacco.AB1B”?

Malware Removal

The Trojan:Win32/Ymacco.AB1B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AB1B virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
iplogger.org
www.bing.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com

How to determine Trojan:Win32/Ymacco.AB1B?


File Info:

crc32: 5F0CCD3C
md5: cff60d1dc052504aa50ea738ced88325
name: CFF60D1DC052504AA50EA738CED88325.mlw
sha1: fae5938931216b8052390f8990883a97aec3e5cb
sha256: 1b03000d2ca0ca6f12d65af9c814e0e0f647185ce3b54c6c5795ee74828acedc
sha512: fafe4bce0e07d2be306b73c02ee334aa12e6f01889f0b6f7f2df58ce8fe21bbac42ac5df3709c6672e7e8e0bd28e2a157bdeb86761e84682fe09858271e4f1fa
ssdeep: 24576:AyIHjLox0UGPHpn302pqa5ugHd+XfyIY9nO+kBDde8eoSg1vpADs+r:Ayyu0UIHp302pcgHd+X6IYaJd0wvpEr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: HappyNewYear
Comments: This installation was built with Inno Setup.
ProductName: HappyNewYear
ProductVersion: 23.47
FileDescription: HappyNewYear Setup
Translation: 0x0000 0x04b0

Trojan:Win32/Ymacco.AB1B also known as:

DrWebTrojan.DownLoader36.34725
MicroWorld-eScanTrojan.GenericKD.36128230
FireEyeTrojan.GenericKD.36128230
ALYacTrojan.GenericKD.36128230
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36128230
K7GWRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.34780.omGfa0j8LHjG
CyrenW32/FileTour.BB.gen!Eldorado
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Generic-9808271-0
KasperskyBackdoor.Win32.Agent.mytymc
AlibabaBackdoor:Win32/Zurgop.07dbdbb2
RisingDownloader.Agent/SFX!1.D0EC (CLASSIC)
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftTrojan.GenericKD.36128230 (B)
AviraTR/Dropper.Gen
MicrosoftTrojan:Win32/Ymacco.AB1B
GridinsoftAdware.Win32.Downloader.oa
ArcabitTrojan.Generic.D22745E6
ZoneAlarmBackdoor.Win32.Agent.mytymc
GDataTrojan.GenericKD.36128230
CynetMalicious (score: 85)
AhnLab-V3PUP/Win32.RL_InstallCore.R362085
McAfeeArtemis!CFF60D1DC052
MAXmalware (ai score=99)
VBA32Trojan.Downloader
MalwarebytesAdware.FileTour
PandaTrj/CI.A
ZonerTrojan.Win32.99098
ESET-NOD32Win32/TrojanDownloader.Zurgop.DA
TrendMicro-HouseCallTROJ_GEN.R002H0CAI21
TencentWin32.Backdoor.Agent.Teta
IkarusTrojan-Downloader.Win32.Zurgop
FortinetW32/Agent.MYTXYG!tr.bdr
WebrootW32.Trojan.Gen
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM42.3.A21B.Malware.Gen

How to remove Trojan:Win32/Ymacco.AB1B?

Trojan:Win32/Ymacco.AB1B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment