PUA

PUA:Win32/Ymacco information

Malware Removal

The PUA:Win32/Ymacco is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Ymacco virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PUA:Win32/Ymacco?


File Info:

name: C802D581D70B7C62753D.mlw
path: /opt/CAPEv2/storage/binaries/7a45aa69ee90c97e1e1a2fde0f78f1015990e91efc6dc38879cc032ad85b3ce8
crc32: 0B1468E1
md5: c802d581d70b7c62753d995c033a970f
sha1: a6d1e181a0d2b9670cf16eca975cf5bd3b52cd8f
sha256: 7a45aa69ee90c97e1e1a2fde0f78f1015990e91efc6dc38879cc032ad85b3ce8
sha512: d7c82edeac3941c9b76061d7139971981d4e25ffc77af82d977a458556b321abc4cb3a84c8cc9c4e676598b37fcaf46664c19f0ccf8828fc4962997cb1021063
ssdeep: 1536:7ZEDAFlYBgqlESvauUpCZcHrqjqlESvauP:7WDEY5lEK/velEK/P
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1118305199D0D66A5E038D1F7C85916B476E38E6A3725A17F8A607E33FB303D38B1424B
sha3_384: 6f2cced98f0c17309d72993d556973c896c5ffdd2505fb4abef35c57ac9bd8399f171c98f68ef32eccd040fbdf790600
ep_bytes: e80600000050e8bb010000558bec81c4
timestamp: 1972-12-25 05:33:23

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

PUA:Win32/Ymacco also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.FlyStudio.4!c
tehtrisGeneric.Malware
FireEyeGeneric.mg.c802d581d70b7c62
SkyhighBehavesLike.Win32.Dropper.mh
McAfeeArtemis!C802D581D70B
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005194cc1 )
K7GWTrojan ( 005194cc1 )
CrowdStrikewin/malicious_confidence_70% (D)
VirITTrojan.Win32.Click2.DFZZ
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
APEXMalicious
SUPERAntiSpywareTrojan.Agent/Gen-FakeAV
AvastWin32:Evo-gen [Trj]
EmsisoftApplication.Generic (A)
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
Webroot
GoogleDetected
VaristW32/S-759a1e41!Eldorado
Antiy-AVLTrojan/Win32.Wacatac.b
Kingsoftmalware.kb.a.986
MicrosoftPUA:Win32/Ymacco
XcitiumTrojWare.Win32.FlyStudio.~UJ@1sa9s6
GDataWin32.Riskware.FlyStudio.C
CynetMalicious (score: 100)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0CA824
IkarusWorm.SuspectCRC
MaxSecureVirus.W32.Flystudio.Y
FortinetW32/FlyStudio.C!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove PUA:Win32/Ymacco?

PUA:Win32/Ymacco removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment