PUA

What is “PUA:Win32/Ymacco”?

Malware Removal

The PUA:Win32/Ymacco is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Ymacco virus can do?

  • Uses Windows utilities for basic functionality
  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine PUA:Win32/Ymacco?


File Info:

name: 2DA7F3C983588422BBAE.mlw
path: /opt/CAPEv2/storage/binaries/90cb135bf6530ffb3669f72e29d0cd777c57c866a13e8c97b93c793d0460b167
crc32: C9810873
md5: 2da7f3c983588422bbaeb03d4ad6297b
sha1: 48edb1718cd551ba853290c7e5b35439e0430c4c
sha256: 90cb135bf6530ffb3669f72e29d0cd777c57c866a13e8c97b93c793d0460b167
sha512: f63e2323d91e6760caa1e732c8b77a6e1a26ebae75af9c946d9c88a5fee87e44d4817400f8724bf78b36b93081202fd6c6e0d4ae1b710d74fac4084ff533637b
ssdeep: 12288:ytb20Qc3lT7af41ePBRYuQLKpqeUhbTv5OFgNuPPpHSgaal0CP4fLFVEH6A:ytb20pkaCqT5TBWgNQ7aE0GeLFuH6A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12015AE1373DE8361C3B25273BA25B701AEBF782506A5F56B2FD4093DE920162521EB73
sha3_384: ac19a159318af360b7feb1c2a03e041c8d252c7cfcfd2ad705d4dc859b13aa39bd36c2903ef43879bf62413c8c6b7eb4
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2014-09-25 13:57:29

Version Info:

FileVersion: 4.0.0.1
ProductVersion: 4.0.0.1
Translation: 0x0809 0x04b0

PUA:Win32/Ymacco also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
SkyhighBehavesLike.Win32.Ransomware.dh
Cylanceunsafe
SangforPUP.Win32.Agent.Vy6e
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
VirITTrojan.Win32.Generic.WTV
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Autoit-6981982-0
SophosGeneric Reputation PUA (PUA)
Trapminemalicious.moderate.ml.score
GoogleDetected
MicrosoftPUA:Win32/Ymacco
XcitiumMalware@#2k8s5p88x90pj
McAfeeArtemis!2DA7F3C98358
MalwarebytesGeneric.Malware/Suspicious
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.3411146.susgen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove PUA:Win32/Ymacco?

PUA:Win32/Ymacco removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment