Trojan

Trojan:Win32/Ymacco.ABFE removal tips

Malware Removal

The Trojan:Win32/Ymacco.ABFE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.ABFE virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Attempts to modify browser security settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

api.zcjczj.cn
config.zcjczj.cn
con2.zcjczj.cn
pv.sohu.com
ip.ws.126.net
info.zcjczj.cn
media.zcjczj.cn
pm.myapp.com
ocsp.dcocsp.cn

How to determine Trojan:Win32/Ymacco.ABFE?


File Info:

crc32: BB7BEB37
md5: a382d5629bc8d44759bc73c3166e3d46
name: evapicturesetup-4855.exe
sha1: 2ae6dd3d8b45d340dc9065b16be1370a99bec615
sha256: fe4ef7eb884fed14e5ca386bd3f6dd470309681a8c718ea3a3447139a41380f6
sha512: 0d2a83b3fb3fee3bfb4ae5aa2c0bda5ccff7adbc37f8bf716ece6398d235a5141f750cca877a30e68611fb8f69b6b79ba876f7584bd31f63b8371176a68ed747
ssdeep: 98304:HdJcUQLUGrupm8EC2+dHI02EQdeYgS5toD80r:/PGZKm8EOh2NUhDF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Setup Engine Copyright xa9 2004-2018 Indigo Rose Corporation
InternalName: suf_launch
FileVersion: 9.5.2.0
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
Comments: Created with Setup Factory
ProductName: Setup Factory Runtime
ProductVersion: 9.5.2.0
FileDescription: Setup Application
OriginalFilename: suf_launch.exe
Translation: 0x0409 0x04e4

Trojan:Win32/Ymacco.ABFE also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.43874035
CAT-QuickHealTrojanDownloader.Chindo
McAfeeArtemis!A382D5629BC8
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Chindo.a!c
SangforMalware
K7AntiVirusTrojan ( 0056e5201 )
BitDefenderTrojan.GenericKD.43874035
K7GWTrojan ( 0056e5201 )
ArcabitTrojan.Generic.D29D76F3
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-7589901-0
KasperskyHEUR:Trojan-Downloader.Win32.Chindo.vho
NANO-AntivirusTrojan.Win32.Chindo.hvoezw
Ad-AwareTrojan.GenericKD.43874035
EmsisoftTrojan.GenericKD.43874035 (B)
F-SecureHeuristic.HEUR/AGEN.1107653
ZillyaDownloader.Chindo.Win32.1252
InvinceaMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.43874035
SophosMal/Generic-S
AviraHEUR/AGEN.1137534
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Ymacco.ABFE
ZoneAlarmHEUR:Trojan-Downloader.Win32.Chindo.vho
GDataTrojan.GenericKD.43874035
ALYacTrojan.GenericKD.43874035
VBA32BScope.Trojan.Ekstak
TrendMicro-HouseCallTROJ_GEN.R002H0CIK20
RisingAdware.Agent!1.C1FF (CLASSIC)
IkarusTrojan.Indiloadz
FortinetW32/Ursu.789031!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.29bc8d
AvastWin32:DropperX-gen [Drp]

How to remove Trojan:Win32/Ymacco.ABFE?

Trojan:Win32/Ymacco.ABFE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment