Trojan

Trojan:Win32/Ymacco.AB3E information

Malware Removal

The Trojan:Win32/Ymacco.AB3E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AB3E virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

Related domains:

wpad.local-net

How to determine Trojan:Win32/Ymacco.AB3E?


File Info:

name: 1A625F919CAC10B20807.mlw
path: /opt/CAPEv2/storage/binaries/3eb44616bd3a45b59f9f06872733c60a06eb0e9d3ab96e434ac41e6f5070a537
crc32: FF6FCAEB
md5: 1a625f919cac10b20807a8f52e67c3ae
sha1: 20b8e83278bbd9bdffec875e4f53f80a37097aaa
sha256: 3eb44616bd3a45b59f9f06872733c60a06eb0e9d3ab96e434ac41e6f5070a537
sha512: 90dcdf84f21b347b2e7544f187fc5e59234f95aa932206657103d266a5518ed169967bd0ca60e54c3be32d741e886af8263867cee5f9bbba0a52fa032a703989
ssdeep: 12288:GTc1OCTK1iSSEYQO+rjCVL0R6WwU4Nj13Jb3GSLtz+RM5+:GA1x0oQO+X24Ra59hz+Rc+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5059E2279C0C033D26201B2966A7B655AFEBE3109329657BBDC0A4C5F745C1FF2A367
sha3_384: 9f79b2e430a808966751c5196f6a93341a5e0d67dbd8878e273056d48251fc89e550927828c535a74a793e91453c0adf
ep_bytes: e84cc70000e9000000006a1468404a4b
timestamp: 2020-09-17 08:44:53

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AB3E also known as:

LionicTrojan.Win32.Biodata.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Zamg.1
FireEyeGeneric.mg.1a625f919cac10b2
CAT-QuickHealTrojan.BiodataPMF.S15940252
ALYacGen:Heur.Mint.Zamg.1
ZillyaTrojan.Biodata.Win32.9538
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004f4c261 )
AlibabaMalware:Win32/km_2cfb44a.None
K7GWAdware ( 004f4c261 )
Cybereasonmalicious.19cac1
BitDefenderThetaGen:NN.ZexaF.34294.WuW@amVn5Qhi
CyrenW32/Wacatac.CI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/IStartSurf.BF potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0GKM21
Paloaltogeneric.ml
KasperskyTrojan.Win32.Biodata.hnhs
BitDefenderGen:Heur.Mint.Zamg.1
NANO-AntivirusTrojan.Win32.Biodata.hvvbgj
SUPERAntiSpywareTrojan.Agent/Gen-Biodata
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10ce0466
Ad-AwareGen:Heur.Mint.Zamg.1
EmsisoftGen:Heur.Mint.Zamg.1 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0GKM21
McAfee-GW-EditionBehavesLike.Win32.IStartSurf.bh
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
GDataGen:Heur.Mint.Zamg.1
JiangminTrojan.Biodata.ajfg
eGambitUnsafe.AI_Score_99%
AviraTR/AD.IStartSurf.BZ
Antiy-AVLTrojan/Generic.ASMalwS.30EE092
ArcabitTrojan.Mint.Zamg.1
ViRobotTrojan.Win32.Z.Biodata.795648.A
MicrosoftTrojan:Win32/Ymacco.AB3E
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Biodata.R351625
McAfeeGenericRXAA-AA!1A625F919CAC
MAXmalware (ai score=89)
VBA32BScope.AdWare.StartSurf
MalwarebytesAdware.IStartSurf
RisingTrojan.Generic@ML.99 (RDML:6QNMbvIF29evVo6MG4/Yxw)
YandexRiskware.Agent!aRIw1s0srqg
IkarusPUA.IStartSurf
MaxSecureTrojan.Malware.106978548.susgen
FortinetW32/Biodata.HNHS!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Trojan:Win32/Ymacco.AB3E?

Trojan:Win32/Ymacco.AB3E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment