Trojan

About “Trojan:Win32/Ymacco.AB91” infection

Malware Removal

The Trojan:Win32/Ymacco.AB91 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AB91 virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed mail clients

How to determine Trojan:Win32/Ymacco.AB91?


File Info:

crc32: 834E4C62
md5: e1a9130d55ccd07229c6cddd8173e5e2
name: upload_file
sha1: a1a3c23cefb94ed28eb0c5f06fe595a251de6f2c
sha256: 9196aa2349f6a559afca6cfa4a983e8dd5188cffd4043c205fdead6f47ec261a
sha512: d7dab64ab1e34063dc0b85be8fcba6659dcf2f68389c8a3d60ed2487c04e5ed053118334a1f9c576a9fc408f8c53f4e2f6ce5f90834571dfce7810f4eed48dd4
ssdeep: 768:Dbs093tGOHn2PAe6nCAQTGWexrecbwEg4ubt7SsE1rjWb571H7Cungg:M0937QAe6CAQiWexKH1+B1rs71H7
type: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AB91 also known as:

ClamAVUnix.Trojan.Mirai-7100807-0
McAfeeGenericRXLU-EV!E1A9130D55CC
SangforMalware
ArcabitTrojan.Trojan.Linux.Gafgyt.8
CyrenE64/Mirai.A.gen!Camelot
SymantecTrojan.Gen.NPE
ESET-NOD32a variant of Linux/Mirai.A
TrendMicro-HouseCallBackdoor.Linux.MIRAI.USELVGT
AvastELF:Mirai-AHC [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Backdoor.Linux.Mirai.b
BitDefenderGen:Variant.Trojan.Linux.Gafgyt.8
NANO-AntivirusTrojan.Elf64.Mirai.hswwtv
AegisLabTrojan.Linux.Mirai.K!c
MicroWorld-eScanGen:Variant.Trojan.Linux.Gafgyt.8
TencentBackdoor.Linux.Mirai.wz
Ad-AwareGen:Variant.Trojan.Linux.Gafgyt.8
F-SecureMalware.LINUX/Mirai.epoqg
DrWebLinux.Mirai.2924
ZillyaTrojan.Mirai.Linux.75491
TrendMicroBackdoor.Linux.MIRAI.USELVGT
FireEyeGen:Variant.Trojan.Linux.Gafgyt.8
SophosMal/Generic-S
IkarusTrojan.Linux.Mirai
Avast-MobileELF:Mirai-FY [Trj]
JiangminBackdoor.Linux.rec
AviraLINUX/Mirai.epoqg
MAXmalware (ai score=99)
Antiy-AVLTrojan[Backdoor]/Linux.Mirai.b
MicrosoftTrojan:Win32/Ymacco.AB91
ZoneAlarmHEUR:Backdoor.Linux.Mirai.b
GDataGen:Variant.Trojan.Linux.Gafgyt.8
AhnLab-V3Linux/Mirai.Gen35
ALYacGen:Variant.Trojan.Linux.Gafgyt.8
SentinelOneDFI – Malicious ELF
FortinetLinux/Mirai.A!tr.bdr
BitDefenderThetaGen:NN.Mirai.34216
AVGELF:Mirai-AHC [Trj]
Qihoo-360virus.elf.mirai.c

How to remove Trojan:Win32/Ymacco.AB91?

Trojan:Win32/Ymacco.AB91 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment