Trojan

Trojan:Win32/Ymacco.ABFC removal tips

Malware Removal

The Trojan:Win32/Ymacco.ABFC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.ABFC virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

pastebin.com
ocsp.digicert.com

How to determine Trojan:Win32/Ymacco.ABFC?


File Info:

crc32: B92179AC
md5: 38d41d70aff980498310edd476f966f0
name: 38D41D70AFF980498310EDD476F966F0.mlw
sha1: e5bac0468ab2a0e3dc06aba23b3af4c8bb099dfe
sha256: fc75e90f5252e17717ad49e4c6a253aea1c51ec282fc8ca5d4e68bb3b4f5267a
sha512: ff625efc076b23ad20f7b25cbc47c26a98d40bc5f4a42e52bae5f6c227d6bcf7313ba9bcb2cb7126d11328bfb5b4a195d2fdcfc0287762ade70d41b33281db7b
ssdeep: 6144:G7rfojVO3bwQKbe2t9dC/X64lrNs9LsTT46q8K4Rt9QdSvOzexxB0mNs01CU4qc4:GHes30Qs5+64lrNsP50Qi9Ns/HImWfB
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.ABFC also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00577ea11 )
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.76243
CylanceUnsafe
ZillyaTrojan.Copak.Win32.29870
SangforTrojan.Win32.Copak.pef
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Copak.b366ca78
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.68ab2a
CyrenW32/Kryptik.EHJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJIX
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderTrojan.GenericKDZ.76243
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanTrojan.GenericKDZ.76243
TencentMalware.Win32.Gencirc.10ce8592
Ad-AwareTrojan.GenericKDZ.76243
SophosML/PE-A + Troj/Agent-BGOS
BitDefenderThetaGen:NN.ZexaF.34266.yyW@aaHosid
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PH121
McAfee-GW-EditionBehavesLike.Win32.RAHack.fc
FireEyeGeneric.mg.38d41d70aff98049
EmsisoftTrojan.GenericKDZ.76243 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Copak.aklo
AviraHEUR/AGEN.1110714
eGambitUnsafe.AI_Score_64%
Antiy-AVLTrojan/Generic.ASMalwS.33F6EFD
MicrosoftTrojan:Win32/Ymacco.ABFC
ArcabitTrojan.Generic.D129D3
GDataTrojan.GenericKDZ.76243
AhnLab-V3Trojan/Win32.Tiggre.C2688118
McAfeeGlupteba-FTTQ!38D41D70AFF9
MAXmalware (ai score=83)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R002C0PH121
RisingTrojan.Kryptik!1.D284 (CLASSIC)
IkarusWin32.Injector.DZQA
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DZQA!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Ymacco.ABFC?

Trojan:Win32/Ymacco.ABFC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment