PUA

PUA:Win32/Ymacco removal guide

Malware Removal

The PUA:Win32/Ymacco is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Ymacco virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PUA:Win32/Ymacco?


File Info:

name: 1DED38CE1C95C574A636.mlw
path: /opt/CAPEv2/storage/binaries/8d18697a6747eafd5d63c76a8bbcb37cb2d8bb13a4e79120940fdc0aeac36510
crc32: 91A4463D
md5: 1ded38ce1c95c574a636783c8d5c0be2
sha1: b61e12c5924e8a8d39c9d0ef396c55a7589e4c4d
sha256: 8d18697a6747eafd5d63c76a8bbcb37cb2d8bb13a4e79120940fdc0aeac36510
sha512: 8d49bff8474b855c42e8d86ce1f09c8c5eb2d940040c81f68243eb1dcdcc710eef8dd75b79a41f303ced45d75d9c64a54d2636b8a710d5061c85f3b270e75754
ssdeep: 49152:++fq15l8WrJrYNmWTmazFlZFuxR5FAdVjOODxQLn+Wn7R1ZjzF2WntVGk5pV:++fsOWtrapnZKRvAXDi7BF2WntVGk/V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F1C533B67B814DFBD86B0130895E3F08CDF9A8312DE1604387CC69856E649F7CA2B65D
sha3_384: e13d5d22a390abc2b395f4926ae991042af024bc33d41f4ae1182d7c84e6f57068d90ebb3473a1c29038e15b1f28a4d3
ep_bytes: 558bec6aff6888c8420068c08c420064
timestamp: 2010-07-31 14:32:56

Version Info:

0: [No Data]

PUA:Win32/Ymacco also known as:

BkavW32.Common.EFC768FC
LionicAdware.Win32.InstallMonster.2!c
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
MalwarebytesGeneric.Malware.AI.DDS
SangforAdware.Win32.InstallMonster.Vyg2
AlibabaAdWare:Win32/InstallMonetizer.296b762e
SymantecPUA.Gen.2
ESET-NOD32Win32/InstallMonetizer.AQ potentially unwanted
Kasperskynot-a-virus:AdWare.Win32.InstallMonster.ixrw
AvastFileRepMalware [Misc]
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
ZoneAlarmnot-a-virus:AdWare.Win32.InstallMonster.ixrw
MicrosoftPUA:Win32/Ymacco
VBA32Adware.InstallMonster
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CKH23
IkarusPUA.InstallMonetizer
FortinetAdware/InstallMonster
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (D)

How to remove PUA:Win32/Ymacco?

PUA:Win32/Ymacco removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment