Categories: Trojan

How to remove “Trojan:Win32/Ymacco.ABD2”?

The Trojan:Win32/Ymacco.ABD2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.ABD2 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

How to determine Trojan:Win32/Ymacco.ABD2?


File Info:

crc32: EC70D2C6md5: 4fe68a78d1f55bd1904fd655f42c7971name: 142_20160408.exesha1: 46396e98895d5b888c3b0b72a0ccd5c407717348sha256: db0050990a20aa9ec53b3e2977342d29c66d7c6f5d0f72cc7aaf119d874c15f4sha512: d255369ed31f46f7aa227e79d5c46645ac0c099ffe3fa971d5bfbf7034c76b9e6365abc1cb058145ef702512d371acb2a181b60835209fb171650cb8876860a0ssdeep: 49152:o87Jg9kNvEiQC4tgj+uGWm/ByWqKT5JIuwhqQuNmBD:F7i95Ej+uA/8WqKTzHBVYBDtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2015InternalName: install.exeFileVersion: 1.0.0.0CompanyName: x5317x4eacx4e91x7acbx65b9x79d1x6280x6709x9650x516cx53f8ProductName: wifiProductVersion: 1.0.0.0FileDescription: x4e3bx9898x5b89x88c5x7a0bx5e8fOriginalFilename: install.exeTranslation: 0x0804 0x04b0

Trojan:Win32/Ymacco.ABD2 also known as:

MicroWorld-eScan Gen:Variant.Adware.Graftor.273185
FireEye Generic.mg.4fe68a78d1f55bd1
CAT-QuickHeal Trojan.MauvaiseRI.S5256593
McAfee PUP-XAL-LM
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
K7AntiVirus Adware ( 004dab441 )
BitDefender Gen:Variant.Adware.Graftor.273185
K7GW Adware ( 004dab441 )
Cybereason malicious.8d1f55
Invincea heuristic
Symantec SMG.Heur!gen
TrendMicro-HouseCall TROJ_GEN.R015C0OFB20
Paloalto generic.ml
GData Gen:Variant.Adware.Graftor.273185
Alibaba AdWare:Win32/Weiduan.b0c149a9
NANO-Antivirus Riskware.Win32.Weiduan.euwrpo
ViRobot Adware.Weiduan.2577920
Tencent Malware.Win32.Gencirc.10b3e885
Ad-Aware Gen:Variant.Adware.Graftor.273185
Sophos BundleInstaller (PUA)
Comodo ApplicUnwnt@#2s349es1956tp
F-Secure Heuristic.HEUR/AGEN.1111954
DrWeb Adware.Weiduan.5
Zillya Adware.Weiduan.Win32.149
TrendMicro TROJ_GEN.R015C0OFB20
Trapmine suspicious.low.ml.score
Emsisoft Gen:Variant.Adware.Graftor.273185 (B)
APEX Malicious
Cyren W32/Adware.FHGX-8755
Webroot W32.Malware.gen
Avira HEUR/AGEN.1111954
MAX malware (ai score=69)
Antiy-AVL Trojan/Win32.TSGeneric
Endgame malicious (high confidence)
Arcabit Trojan.Adware.Graftor.D42B21
Microsoft Trojan:Win32/Ymacco.ABD2
Cynet Malicious (score: 85)
AhnLab-V3 PUP/Win32.BundleInstaller.R179553
Acronis suspicious
VBA32 Adware.Weiduan
Malwarebytes Adware.Weiduan
Panda Trj/Genetic.gen
ESET-NOD32 a variant of Win32/Adware.Weiduan.G
Rising Trojan.Vigorf!8.EAEA (CLOUD)
Yandex PUA.Weiduan!
Ikarus PUA.Weiduan
Fortinet Riskware/BundleInstaller
AVG Win32:Adware-gen [Adw]
Avast Win32:Adware-gen [Adw]
CrowdStrike win/malicious_confidence_70% (D)
Qihoo-360 Generic/HEUR/QVM41.2.E267.Malware.Gen

How to remove Trojan:Win32/Ymacco.ABD2?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “Trojan.Generic.35584711”?

The Trojan.Generic.35584711 is considered dangerous by lots of security experts. When this infection is active,…

3 mins ago

Trojan.Agent.GHNB removal

The Trojan.Agent.GHNB is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

About “Win32/AutoRun.AFT” infection

The Win32/AutoRun.AFT is considered dangerous by lots of security experts. When this infection is active,…

18 mins ago

BScope.Trojan.VBCR.1912 removal tips

The BScope.Trojan.VBCR.1912 is considered dangerous by lots of security experts. When this infection is active,…

33 mins ago

Zusy.542015 (B) removal guide

The Zusy.542015 (B) is considered dangerous by lots of security experts. When this infection is…

44 mins ago

Malware.AI.3876614151 (file analysis)

The Malware.AI.3876614151 is considered dangerous by lots of security experts. When this infection is active,…

50 mins ago