Trojan

What is “Trojan:Win32/Ymacco.AB5C”?

Malware Removal

The Trojan:Win32/Ymacco.AB5C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AB5C virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to modify browser security settings
  • Anomalous binary characteristics

Related domains:

api.shatangmu.cn
config.shatangmu.cn
con2.shatangmu.cn
pv.sohu.com
ip.ws.126.net
info.shatangmu.cn
media.shatangmu.cn

How to determine Trojan:Win32/Ymacco.AB5C?


File Info:

crc32: 06DFC1D4
md5: b4d0fd99b38ac1e4150a1ed63693ebab
name: B4D0FD99B38AC1E4150A1ED63693EBAB.mlw
sha1: a2735bb11a1cbcbd9087a9b41690c6a3948461c6
sha256: 5c74cec6b78830fc999930a7fb5b5297563f6867727df711a1033980075302ac
sha512: f247d92f87020722be31d6cc5ef35eb908dd788af4ba3398a60ec1a13d35b6469d0845385afef0b98d5eb83460d83fa5c7d729453d5753a21f215f0c19e3a770
ssdeep: 49152:iXKgbSUIxUCG4LNcDYH8Grkl5Dm8E0jLRfv8MX3UYxki1wLuIq5lN6juNx:WJcUQLUGrupm8EC1fEMXNZf7n
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: JiJiResouse
FileVersion: 1.0.0.1
CompanyName: JiJiResouse
Comments: JiJiResouse
ProductName: JiJiResouse
ProductVersion: 1.0.0.1
FileDescription: JiJiResousex5b89x88c5x7a0bx5e8f
OriginalFilename: suf_launch.exe
Translation: 0x0409 0x0000

Trojan:Win32/Ymacco.AB5C also known as:

MicroWorld-eScanTrojan.GenericKD.35148894
FireEyeTrojan.GenericKD.35148894
CAT-QuickHealTrojanDownloader.Chindo
ALYacTrojan.GenericKD.35148894
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.GenericKD.35148894
K7GWTrojan ( 0056e5201 )
K7AntiVirusTrojan ( 0056e5201 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyTrojan-Downloader.Win32.Chindo.efg
AlibabaTrojanDownloader:Win32/Chindo.84963d95
NANO-AntivirusTrojan.Win32.Chindo.ibotxx
AegisLabTrojan.Win32.Chindo.a!c
RisingAdware.Agent!1.C221 (CLASSIC)
Ad-AwareTrojan.GenericKD.35148894
EmsisoftTrojan.GenericKD.35148894 (B)
ComodoMalware@#32zbpztqvku7w
F-SecureHeuristic.HEUR/AGEN.1136317
TrendMicroTROJ_GEN.R002C0GJO20
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.Indiloadz
AviraHEUR/AGEN.1136317
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AB5C
GridinsoftTrojan.Downloader.dd!c
ArcabitTrojan.Generic.D218545E
ZoneAlarmTrojan-Downloader.Win32.Chindo.efg
GDataTrojan.GenericKD.35148894
CynetMalicious (score: 85)
McAfeeArtemis!B4D0FD99B38A
MAXmalware (ai score=88)
VBA32BScope.Trojan.Ekstak
PandaTrj/CI.A
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002C0GJO20
TencentMalware.Win32.Gencirc.10ce2d80
MaxSecureTrojan.Malware.73774577.susgen
FortinetW32/Ursu.789031!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.9b38ac
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.c96

How to remove Trojan:Win32/Ymacco.AB5C?

Trojan:Win32/Ymacco.AB5C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment