Trojan

What is “Trojan:Win32/Ymacco.ABB3”?

Malware Removal

The Trojan:Win32/Ymacco.ABB3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.ABB3 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Ymacco.ABB3?


File Info:

name: 37D6755323B58A38D265.mlw
path: /opt/CAPEv2/storage/binaries/b3f8cf2d60003da2fffecfdbd2e7b6acd5724b9a770a5d4afbb6ba3d37740fb2
crc32: BAF67F93
md5: 37d6755323b58a38d2654264dbc6dc99
sha1: eac54d3fb761e1486539671bff90b4750e016ed8
sha256: b3f8cf2d60003da2fffecfdbd2e7b6acd5724b9a770a5d4afbb6ba3d37740fb2
sha512: fe7ed3d289ebe1c6445f21df9269bbe37267c340cf848f8606528267e806426dd12bad5650e1a6dd18576b365e1a38a10be67505afd6655e242185a7ddc507a1
ssdeep: 24576:M45B4KXSUeYkYrr87V6oNPiNmISjIj/l3juQ55313N:M4D4KrlMjIj/l3F
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T121A5FA036A8B0E75DDD23BB461CB533AA734FE30CA2A9B7FB609C53559532C46C1A742
sha3_384: 8183404855d92e016e38624399758efb85fd6d79d0f6a0a04cd1975697d6a4470b962995c3ebd182016fce531e49b231
ep_bytes: 83ec0cc70598744e0000000000e8dec3
timestamp: 2021-12-09 03:27:23

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.ABB3 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zapchast.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.81116
FireEyeTrojan.GenericKDZ.81116
CAT-QuickHealTrojan.SabsikIH.S21959152
McAfeeGenericRXQY-JE!37D6755323B5
CylanceUnsafe
K7AntiVirusTrojan ( 00588c0e1 )
AlibabaTrojan:Win32/Zapchast.83f2ad85
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.BC
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Generickdz-9888427-0
KasperskyHEUR:Trojan.Win32.Zapchast.gen
BitDefenderTrojan.GenericKDZ.81116
TencentMalware.Win32.Gencirc.11db5c7d
Ad-AwareTrojan.GenericKDZ.81116
SophosMal/Generic-S
TrendMicroTROJ_GEN.R02DC0PLB21
McAfee-GW-EditionGenericRXQY-JE!37D6755323B5
EmsisoftTrojan.GenericKDZ.81116 (B)
JiangminTrojan.Zapchast.abh
MaxSecureTrojan.Malware.300983.susgen
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Ymacco.ABB3
ViRobotTrojan.Win32.Z.Zapchast.2253253.AA
GDataWin32.Trojan.PSE.11GYR71
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Muldrop.R436343
VBA32Trojan.Zapchast
ALYacTrojan.GenericKDZ.81116
MAXmalware (ai score=83)
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_GEN.R02DC0PLB21
RisingTrojan.Starter!1.D93D (CLASSIC)
FortinetW32/Agent.ADMG!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A

How to remove Trojan:Win32/Ymacco.ABB3?

Trojan:Win32/Ymacco.ABB3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment