Trojan

How to remove “Trojan:Win32/Ymacco.ABDD”?

Malware Removal

The Trojan:Win32/Ymacco.ABDD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.ABDD virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Ymacco.ABDD?


File Info:

crc32: 890092C3
md5: 8bdc4ebc00b11bfbcece041c6237714f
name: 8BDC4EBC00B11BFBCECE041C6237714F.mlw
sha1: 2be93298b6192462560985bb3706f3694ddbd8e5
sha256: dd1ee58dbf218181254f52f1e1cbc254ec13b2fac12cc606ca8c6052896fa58d
sha512: d8029a7121243eac49c221338b1eb5441884d51ae7d8a2b2804b18cfcedea25f2ed94e9dedab65fbb78a1f70abc9e04b79fd70e41b29da341fcb3aa1abb282f3
ssdeep: 48:6fQLUmruXUfQ3qAGeLWDJtUSuP3qx3DgXulPlFRFWSfbNtm:TjruXp6AGeLAUS4qZVdlFjzNt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: tlc.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: tlc.exe

Trojan:Win32/Ymacco.ABDD also known as:

MicroWorld-eScanGen:Variant.Ursu.702
McAfeeArtemis!8BDC4EBC00B1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004f9af71 )
BitDefenderGen:Variant.Ursu.702
K7GWTrojan ( 004f9af71 )
Cybereasonmalicious.c00b11
CyrenW32/S-f5d6a516!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.Zusy.eoiteu
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareGen:Variant.Ursu.702
EmsisoftGen:Variant.Ursu.702 (B)
ComodoTrojWare.MSIL.Zusy.WS@6l6lgw
F-SecureHeuristic.HEUR/AGEN.1122400
DrWebTrojan.Starter.7894
ZillyaTrojan.Injector.Win32.411770
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.8bdc4ebc00b11bfb
SophosMal/Generic-R + Troj/Kryptik-HS
IkarusTrojan.MSIL.Injector
WebrootTrojan.Msil.Smeazymo
AviraHEUR/AGEN.1122400
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Ymacco.ABDD
ArcabitTrojan.Ursu.702
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Ursu.702
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R288829
ALYacGen:Variant.Ursu.702
MAXmalware (ai score=100)
MalwarebytesTrojan.Agent.MSIL
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Injector.QJL
RisingTrojan.Injector!8.C4 (TFE:C:2nOdauBXyMQ)
YandexTrojan.Injector!DoK/d0RXR3A
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_80%
FortinetMSIL/Injector.QJL!tr
BitDefenderThetaGen:NN.ZemsilF.34804.am0@aWy2!kb
AVGWin32:Rootkit-gen [Rtk]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Win32/RootKit.Rootkit.7e5

How to remove Trojan:Win32/Ymacco.ABDD?

Trojan:Win32/Ymacco.ABDD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment