Trojan

Trojan:Win32/Ymacco.ABC1 removal instruction

Malware Removal

The Trojan:Win32/Ymacco.ABC1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.ABC1 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Trojan:Win32/Ymacco.ABC1?


File Info:

name: 223B61F2ED630D66CE44.mlw
path: /opt/CAPEv2/storage/binaries/c15cfe35357fdd8329a01cd426986c1617b05bf37c127b0210e755352186b85c
crc32: F669636E
md5: 223b61f2ed630d66ce4469860f267ef6
sha1: 7d0da5a4189add87d3cdd36128ffa03e1e82a6f6
sha256: c15cfe35357fdd8329a01cd426986c1617b05bf37c127b0210e755352186b85c
sha512: 204f8ff64f3c7e5cd7012ffbc9171ba64d5ad8579aea874cf719ec1351433b4dbca61180bab7274fc6fee7579d54529c26f0092bddd99ee5bf2c1a60d038e395
ssdeep: 12288:LyJGE781C1nL+O1PLAr7ZRma9u+KXl5UETmARfTQ5GVPADJGJHyHyk7X0dC3hCct:61Pkr56FTRNrPmSCX0o3hCK
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18ED4D0007682F03AE8F315724FFDAAFA962CBD100B1559FBA3C859AE4B255D17531F22
sha3_384: 704ef605a75fbbd4f124873282a14dcadcaf87920169819aeb6921e5f5c935d543d81b1863834190b72fc5beb846a4f6
ep_bytes: e883080000e974feffff8b4df464890d
timestamp: 2019-11-01 19:29:56

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.ABC1 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Bingoml.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop11.30889
MicroWorld-eScanGen:Variant.Razy.575921
FireEyeGeneric.mg.223b61f2ed630d66
McAfeeGenericRXAA-AA!223B61F2ED63
CylanceUnsafe
ZillyaTrojan.Bingoml.Win32.7928
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.2ed630
BitDefenderThetaGen:NN.ZexaF.34062.LqZ@aejal1i
CyrenW32/Bingoml.D.gen!Eldorado
ESET-NOD32Win32/GameHack.FCC potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002C0WL421
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Bingoml.gen
BitDefenderGen:Variant.Razy.575921
NANO-AntivirusTrojan.Win32.Razy.gkocel
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10cf8ec6
Ad-AwareGen:Variant.Razy.575921
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WL421
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Razy.575921 (B)
JiangminTrojan.Bingoml.cky
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2D3FA66
MicrosoftTrojan:Win32/Ymacco.ABC1
GDataGen:Variant.Razy.575921
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3546915
VBA32Trojan.MulDrop
ALYacGen:Variant.Razy.575921
MalwarebytesMalware.AI.182181509
APEXMalicious
RisingTrojan.Generic@ML.86 (RDMK:ty4A46moKJvE9N2RNb1CjA)
YandexRiskware.Agent!4ZmQP2vTLmo
MAXmalware (ai score=83)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Razy.5759!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan:Win32/Ymacco.ABC1?

Trojan:Win32/Ymacco.ABC1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment