Trojan

Trojan:Win32/Ymacco.ABD1 removal

Malware Removal

The Trojan:Win32/Ymacco.ABD1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.ABD1 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Ymacco.ABD1?


File Info:

crc32: A604977B
md5: 18c29dce217646389081803bb9e99a78
name: upload_file
sha1: 410a15a9fb9ec5b0648611e7735d7c4a0792e311
sha256: d114cc0c23ae252a1f3b89ad706b5784e0c962314345d4565354ff7dff9e7883
sha512: 28845dc3563c89fabec749090a5d0e895355b30b1d1b7645c58e6dfe3722f631b4bab2c62cffca137e7bc422a3c5c3432a71fcdd8dfd02b52659bcd8d191d404
ssdeep: 24576:SRBrzwX0YmJI8DRnCD4jtnT8Q1r0ly78ipwR7:kJzdnm4lT8Q1r0pieR7
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: (c) . All rights reserved.
InternalName: CommonUtils.dll
FileVersion: 1.0.0.1
CompanyName: Industrial and Commercial Bank of China
ProductName: CommonUtils
ProductVersion: 1.0.0.1
FileDescription: CommonUtils
OriginalFilename: CommonUtils.dll
Translation: 0x0409 0x04e4

Trojan:Win32/Ymacco.ABD1 also known as:

MicroWorld-eScanGeneric.Application.CoinMiner.1.995B505B
FireEyeGeneric.Application.CoinMiner.1.995B505B
CAT-QuickHealPUA.CoinminerPMF.S9547169
McAfeeGenericRXAA-AA!18C29DCE2176
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Miner.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGeneric.Application.CoinMiner.1.995B505B
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e21764
Invinceaheuristic
F-ProtW32/CoinMiner.BW
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
ClamAVWin.Coinminer.Generic-7151250-0
GDataWin32.Application.Coinminer.BU
KasperskyTrojan.Win32.Miner.assmw
AlibabaTrojan:Win32/Miner.48859f61
NANO-AntivirusRiskware.Win32.BtcMine.gmfedn
AvastWin32:Malware-gen
RisingTrojan.Miner!8.EA1 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGeneric.Application.CoinMiner.1.995B505B (B)
ComodoApplication.Win32.CoinMiner.BS@8rlsid
F-SecureHeuristic.HEUR/AGEN.1133596
DrWebTool.BtcMine.2235
ZillyaTrojan.Miner.Win32.9908
TrendMicroTROJ_GEN.R004C0PFF20
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
MaxSecureTrojan.Malware.121218.susgen
Trapminemalicious.high.ml.score
SophosXMRig Miner (PUA)
IkarusPUA.CoinMiner
CyrenW32/CoinMiner.YUOF-4693
JiangminRiskTool.BitCoinMiner.mdf
AviraHEUR/AGEN.1133596
Antiy-AVLTrojan/Win32.Miner
ArcabitGeneric.Application.CoinMiner.1.995B505B
ZoneAlarmTrojan.Win32.Miner.assmw
MicrosoftTrojan:Win32/Ymacco.ABD1
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.CoinMiner.R336602
VBA32BScope.Trojan.Miner
MAXmalware (ai score=89)
Ad-AwareGeneric.Application.CoinMiner.1.995B505B
MalwarebytesTrojan.BitCoinMiner
ESET-NOD32a variant of Win32/CoinMiner.ES potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R004C0PFF20
TencentMalware.Win32.Gencirc.10ba432e
YandexRiskware.Agent!
FortinetW32/CryptoMiner.L!tr
BitDefenderThetaGen:NN.ZexaF.34128.dnKfaGnQuqoi
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
Qihoo-360Win32/Trojan.e8d

How to remove Trojan:Win32/Ymacco.ABD1?

Trojan:Win32/Ymacco.ABD1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment