Trojan

Trojan:Win32/Ymacco.ABEE (file analysis)

Malware Removal

The Trojan:Win32/Ymacco.ABEE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.ABEE virus can do?

  • At least one process apparently crashed during execution
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.zcjczj.cn
config.zcjczj.cn
con2.zcjczj.cn
pv.sohu.com
ip.ws.126.net
info.zcjczj.cn

How to determine Trojan:Win32/Ymacco.ABEE?


File Info:

crc32: 72B3F5E0
md5: 5b144d95631e97d11e66677f3d12cfed
name: evapicturesetup-4826.exe
sha1: c53b16db15a372cdfae25bfb292e09e435b525ff
sha256: ee3e735744853145103c40979edd6bf2ea1040765e8ded282c4c7642e4a8140f
sha512: f5203bcc57dfe263f574b5c80caa71ed8008e7f7fe7a44b177dc744c9929d8331eb890a300ca900216d62e43660aea8a36686c77b26bd55622ade699aa5cb8b3
ssdeep: 98304:cdJcUQLUGrupm8EC9DsM6eWKyehhireYjdsUoa4NIk:QPGZKm8Eq5NphhiKY34Ik
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Setup Engine Copyright xa9 2004-2018 Indigo Rose Corporation
InternalName: suf_launch
FileVersion: 9.5.2.0
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
Comments: Created with Setup Factory
ProductName: Setup Factory Runtime
ProductVersion: 9.5.2.0
FileDescription: Setup Application
OriginalFilename: suf_launch.exe
Translation: 0x0409 0x04e4

Trojan:Win32/Ymacco.ABEE also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34496711
CAT-QuickHealTrojanDownloader.Chindo
Qihoo-360Win32/Trojan.Downloader.31d
ALYacTrojan.GenericKD.34496711
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Chindo.a!c
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKD.34496711
K7GWTrojan-Downloader ( 005610291 )
K7AntiVirusTrojan-Downloader ( 005610291 )
TrendMicroTROJ_GEN.R03BC0WIC20
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R03BC0WIC20
AvastWin32:Trojan-gen
ClamAVWin.Malware.Generic-7589901-0
KasperskyTrojan-Downloader.Win32.Chindo.dwv
AlibabaTrojanDownloader:Win32/Chindo.b589a069
NANO-AntivirusTrojan.Win32.Chindo.huihlk
APEXMalicious
Ad-AwareTrojan.GenericKD.34496711
EmsisoftTrojan.GenericKD.34496711 (B)
ComodoMalware@#1l8allv2inc9h
F-SecureHeuristic.HEUR/AGEN.1107653
ZillyaDownloader.Chindo.Win32.1252
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.BadFile.rc
FireEyeGeneric.mg.5b144d95631e97d1
SophosMal/Generic-S
IkarusTrojan.Indiloadz
AviraHEUR/AGEN.1107653
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Ymacco.ABEE
ArcabitTrojan.Generic.D20E60C7
ZoneAlarmTrojan-Downloader.Win32.Chindo.dwv
GDataTrojan.GenericKD.34496711
McAfeeArtemis!5B144D95631E
VBA32BScope.Trojan.Ekstak
PandaTrj/CI.A
FortinetW32/Ursu.789031!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
MaxSecureTrojan.Malware.1728101.susgen

How to remove Trojan:Win32/Ymacco.ABEE?

Trojan:Win32/Ymacco.ABEE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment