Trojan

About “Trojan:Win32/Ymacco.ABFB” infection

Malware Removal

The Trojan:Win32/Ymacco.ABFB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.ABFB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Ymacco.ABFB?


File Info:

crc32: 24680F83
md5: 5796cf389aa0b8265f4df4db181a3e94
name: 5796CF389AA0B8265F4DF4DB181A3E94.mlw
sha1: 1f285b812e24ad36b1c9981540a45f7b06c2be3e
sha256: fb470a7a36ead1bdddb6270cadcf283da8ca415cc13c7169df6ab372a4180661
sha512: 5407c67a2b914e2a366cc9c41d009d852a72831051d8aa16fd35e3b03af375c39f28c483b4f7c6a3c35dd3c9a8430b9bc989b6c0f43e20909db6b9c4a3ead74b
ssdeep: 6144:MhC2F8NXC796TB9vj48ya18GX2SGrgqhP0rrOwS/:MbeVQkTrvj45G4rpP6ywa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.ABFB also known as:

MicroWorld-eScanGen:Variant.Symmi.81583
FireEyeGeneric.mg.5796cf389aa0b826
CAT-QuickHealTrojan.Generic
Qihoo-360HEUR/Malware.QVM10.Gen
ALYacGen:Variant.Symmi.81583
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0053b4521 )
BitDefenderGen:Variant.Symmi.81583
K7GWTrojan ( 0053b4521 )
Cybereasonmalicious.89aa0b
BitDefenderThetaGen:NN.ZexaF.34804.nqW@a82R8Ee
CyrenW32/A-3e7aeab6!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.AQH
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/Injector.80226030
NANO-AntivirusTrojan.Win32.Symmi.buhysu
ViRobotTrojan.Win32.Z.Zusy.218112.AP
RisingTrojan.Generic!8.C3 (CLOUD)
Ad-AwareGen:Variant.Symmi.81583
SophosMal/Generic-S
ComodoMalware@#19ieneth617q4
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebWin32.HLLW.Autoruner.25074
ZillyaTrojan.Generic.Win32.11163
TrendMicroTROJ_GEN.R002C0GAS21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftGen:Variant.Symmi.81583 (B)
IkarusTrojan-Crypt.Xpack
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.ABFB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Symmi.D13EAF
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Symmi.81583
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!5796CF389AA0
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002C0GAS21
TencentWin32.Trojan.Generic.Swuw
YandexTrojan.Agent!PzrZ51LMCCs
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/Ymacco.ABFB?

Trojan:Win32/Ymacco.ABFB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment