Trojan

Trojan:Win32/Ymacco.AB79 removal instruction

Malware Removal

The Trojan:Win32/Ymacco.AB79 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AB79 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

sunray1975.zapto.org

How to determine Trojan:Win32/Ymacco.AB79?


File Info:

crc32: CC2FF038
md5: b25770be6a657249a1dfe342a63430e1
name: B25770BE6A657249A1DFE342A63430E1.mlw
sha1: 915727a980759606c2d6358b6c9e92d546b38217
sha256: 796b0582e50585b5d73ba11f82e3015264cb6e045779a6efea261a7844c8da57
sha512: ac0aab241f3c58ecd3bcaa4c86e987a589a4e6e2d6311fc1a8eb6676ec4396a39cf468cd17c537a512257a1376cebaed107a561875533f03ed5b622fe43b5de5
ssdeep: 49152:YjuIG9XJLrduEyztsR7OQzQzAmjqamm173:YKIGdd/yzt67OU7ap
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AB79 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00548e051 )
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader6.7779
CynetMalicious (score: 100)
CAT-QuickHealTrojan.WacatacPMF.S16755091
ALYacGen:Variant.Symmi.34741
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.74242
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 00548e051 )
Cybereasonmalicious.e6a657
CyrenW32/Injector.OZVT-2500
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.AHHO
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:MBRlock-DV [Trj]
ClamAVWin.Trojan.Mbrlock-9779766-0
KasperskyUDS:Trojan-Ransom.Win32.Blocker
BitDefenderGen:Variant.Symmi.34741
NANO-AntivirusTrojan.Win32.Dapato.bsjzfg
MicroWorld-eScanGen:Variant.Symmi.34741
TencentTrojan.Win32.Blocker.zg
Ad-AwareGen:Variant.Symmi.34741
SophosMal/Generic-S
ComodoTrojWare.Win32.Injector.HO@82j6jo
BitDefenderThetaAI:Packer.285FEA2921
TrendMicroTROJ_GEN.R03BC0PJR21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.b25770be6a657249
EmsisoftGen:Variant.Symmi.34741 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.pkq
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.30F91B2
MicrosoftTrojan:Win32/Ymacco.AB79
GDataWin32.Trojan.PSE.4HB152
AhnLab-V3Dropper/Win32.Dapato.R83155
McAfeeGenericRXIP-BJ!B25770BE6A65
MAXmalware (ai score=88)
VBA32TrojanRansom.Blocker
MalwarebytesRansom.Blocker
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0PJR21
RisingTrojan.Injector!1.DA56 (CLASSIC)
YandexTrojan.Injector!6XR9EGb/HqY
IkarusTrojan-Ransom.Blocker
MaxSecureTrojan.Malware.11913.susgen
FortinetW32/Injector.AHHO!tr
AVGWin32:MBRlock-DV [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Ymacco.AB79?

Trojan:Win32/Ymacco.AB79 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment