Trojan

Trojan:Win32/Ymacco.AB84 malicious file

Malware Removal

The Trojan:Win32/Ymacco.AB84 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AB84 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
pastebin.com
ocsp.digicert.com
1fichier.com

How to determine Trojan:Win32/Ymacco.AB84?


File Info:

crc32: 3B247346
md5: ec5d642d2582bdc3fea1398140e31ffd
name: EC5D642D2582BDC3FEA1398140E31FFD.mlw
sha1: ae9a744cfdf6267ebb5eb4c910f5fa87e82abdcc
sha256: 84b582cb7a3365998c2f2093f58bf33c5504a50fd775091d2cff0666428b1d04
sha512: 5e8e183ae3dbab67fe7cad20cb4271667aa1c15a5a10e552cd455d4a3909f10b19feebde47ad3da5ef779250e67d21ec84c07d5d2bb56e6663380598cbc61530
ssdeep: 49152:a9N26FOnzGn6LJvqkwnpC+mWd6uIcczbPy:a906FOznLo0+Dd6uxczb6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 9.1.0.0
ProductName: Setup
FileVersion: 9.1.0.0
OriginalFilename: suf_launch.exe
FileDescription: Setup Application
Translation: 0x0409 0x0000

Trojan:Win32/Ymacco.AB84 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36271634
FireEyeTrojan.GenericKD.36271634
ALYacTrojan.GenericKD.36271634
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Adload.a!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36271634
K7GWRiskware ( 0040eff71 )
CyrenW32/Indiloadz.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0WAV21
AvastWin32:Malware-gen
KasperskyTrojan-Downloader.Win32.Adload.scio
AlibabaTrojanDownloader:Win32/Adload.c844d295
RisingDownloader.Adload!8.D1 (CLOUD)
Ad-AwareTrojan.GenericKD.36271634
SophosMal/Generic-S
ZillyaDownloader.Adload.Win32.100296
TrendMicroTROJ_GEN.R002C0WAV21
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
EmsisoftTrojan.GenericKD.36271634 (B)
IkarusTrojan.SuspectCRC
MicrosoftTrojan:Win32/Ymacco.AB84
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D2297612
ZoneAlarmTrojan-Downloader.Win32.Adload.scio
GDataTrojan.GenericKD.36271634
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4251457
McAfeeArtemis!EC5D642D2582
MAXmalware (ai score=83)
MalwarebytesMalware.AI.370984832
PandaTrj/CI.A
APEXMalicious
ESET-NOD32a variant of Generik.NTMEHDY
TencentWin32.Trojan-downloader.Adload.Alsn
eGambitUnsafe.AI_Score_99%
FortinetW32/Indiloadz.CA!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Adware.AdLoad.HgIASOMA

How to remove Trojan:Win32/Ymacco.AB84?

Trojan:Win32/Ymacco.AB84 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment