Trojan

How to remove “Trojan:Win32/Ymacco.AB52”?

Malware Removal

The Trojan:Win32/Ymacco.AB52 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AB52 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Performs some HTTP requests
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
pastebin.com
cutit.org
q.gs
aporasal.net

How to determine Trojan:Win32/Ymacco.AB52?


File Info:

crc32: A8EF771B
md5: 4f27bced8bf78d17141cfe5716b9b454
name: 4F27BCED8BF78D17141CFE5716B9B454.mlw
sha1: d7aabefd3477d1a4743421e753c8ab47edf5b5c3
sha256: 52c95f41a14d9234214eedafb3ccd2768a66af2a7868912c7f3bbbce204c3265
sha512: 6fd7a8e129570bb210edefe8cc75b9de2e1065227a5da85180e01d8867c2f6d4c5d69aaedee709532cb2ff2d21cad5ac651993cf2a82a8ec8ff6b5a1ff71479a
ssdeep: 24576:LuOFjXakOcDu8aqWSv1vx58lTyKigD6rRSHse:LuOFakO+u83vBx5wyAD6rwHz
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AB52 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.576052
FireEyeGeneric.mg.4f27bced8bf78d17
CAT-QuickHealTrojan.Generic
ALYacGen:Variant.Razy.576052
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0057372a1 )
BitDefenderGen:Variant.Razy.576052
K7GWTrojan ( 0057372a1 )
Cybereasonmalicious.d8bf78
BitDefenderThetaGen:NN.ZexaF.34804.ZmZ@aa@cnPk
CyrenW32/S-91c2cc44!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R049C0PB221
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.07c00b79
NANO-AntivirusTrojan.Win32.Razy.iegtwa
AegisLabTrojan.Win32.Generic.4!c
TencentMalware.Win32.Gencirc.11b23c78
Ad-AwareGen:Variant.Razy.576052
SophosMal/Generic-R + Troj/Agent-BFYM
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureHeuristic.HEUR/AGEN.1136878
TrendMicroTROJ_GEN.R049C0PB221
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
EmsisoftGen:Variant.Razy.576052 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.gonhs
AviraHEUR/AGEN.1136878
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Ymacco.AB52
ArcabitTrojan.Razy.D8CA34
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.576052
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R263763
McAfeeGenericRXMT-EY!4F27BCED8BF7
VBA32BScope.Trojan.Wacatac
MalwarebytesGlupteba.Backdoor.Bruteforce.DDS
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/Injector.EBQH
RisingTrojan.Injector!1.D070 (CLASSIC)
YandexTrojan.Agent!4fVMOi6dbKk
MAXmalware (ai score=86)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.EBQH!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.Generic.HxMBAbsA

How to remove Trojan:Win32/Ymacco.AB52?

Trojan:Win32/Ymacco.AB52 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment