Trojan

What is “Trojan:Win32/Ymacco.AB37”?

Malware Removal

The Trojan:Win32/Ymacco.AB37 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AB37 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Ymacco.AB37?


File Info:

crc32: 6150F6F5
md5: a077c46e173679e3b1ee90271bed6ecd
name: A077C46E173679E3B1EE90271BED6ECD.mlw
sha1: de690326c091cea9877015cf7309c414365166ae
sha256: 37d9fef48ac6486644003ad6921b336680c2eba823a43067f10d3d26a764eeff
sha512: 449980210b0dbc328874248a2d9b0510f90cbfde39bdad5f10a26051374ac843b486295cebabc33349a860478b50fa591262b92d4eacaac7acfa8ce1cd902a63
ssdeep: 12288:xK84OFhq51hKh7I/FD/7CDbW7EKIe9co5y7FXgJZM9zK7XBTOC:xK8Fw27Iwbcsky7pg7kC
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AB37 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35256809
Qihoo-360Generic/HEUR/QVM03.0.4EBB.Malware.Gen
McAfeeGenericRXMO-KY!A077C46E1736
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.MSIL.Crypt.4!c
SangforMalware
K7AntiVirusTrojan ( 0056ea7c1 )
BitDefenderTrojan.GenericKD.35256809
K7GWTrojan ( 0056ea7c1 )
Cybereasonmalicious.6c091c
TrendMicroTROJ_GEN.R002C0PKG20
CyrenW32/MSIL_Kryptik.CDP.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.MSIL.Crypt.gen
AlibabaTrojan:Win32/csharp.ali2000008
ViRobotTrojan.Win32.Z.Kryptik.750080.EH
Ad-AwareTrojan.GenericKD.35256809
EmsisoftTrojan.GenericKD.35256809 (B)
F-SecureTrojan.TR/AD.AgentTesla.qkmkh
DrWebTrojan.PackedNET.461
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
FireEyeTrojan.GenericKD.35256809
SophosMal/Generic-S
IkarusTrojan.MSIL.Inject
WebrootW32.Malware.Gen
AviraTR/AD.AgentTesla.qkmkh
MAXmalware (ai score=84)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AB37
ArcabitTrojan.Generic.D219F9E9
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
GDataTrojan.GenericKD.35256809
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Inject.R355833
BitDefenderThetaGen:NN.ZemsilF.34634.TmW@a8nsbUji
ALYacTrojan.GenericKD.35256809
VBA32Trojan.MSIL.Crypt
MalwarebytesTrojan.Injector
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Kryptik.XTU
TrendMicro-HouseCallTROJ_GEN.R002C0PKG20
TencentWin32.Trojan.Inject.Auto
FortinetMSIL/Kryptik.XTU!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan:Win32/Ymacco.AB37?

Trojan:Win32/Ymacco.AB37 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment