PUA

PUA:Win32/Ymacco removal guide

Malware Removal

The PUA:Win32/Ymacco is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUA:Win32/Ymacco virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUA:Win32/Ymacco?


File Info:

name: 9A91859CBB54F68D7493.mlw
path: /opt/CAPEv2/storage/binaries/3c5cf827c98b5e0b4494f4220c211ac4a5632704b8bbc56adfc023a357db6d28
crc32: 21E438A1
md5: 9a91859cbb54f68d7493e0c1ab622c6a
sha1: 6771cba37b424580480bf82353c525bab4c5cad4
sha256: 3c5cf827c98b5e0b4494f4220c211ac4a5632704b8bbc56adfc023a357db6d28
sha512: fce0b4090b35ee70befd0d7d004092e1110fe7ab70a1a7dc8af4a2abcf4b6652a7839af77242451e8a330b3064cbf6541cc0127127bf7a4567ffc4e34c8815da
ssdeep: 12288:tmjLCtqtmGQzRUsjDVO/1dBw/FMGzBkOXoSPnM:tsIqta2uO/1dq/WGVM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107942348F2C5725DE96911362F9FAB148F08FE8CA15147EA308D361F6F93A160EC6376
sha3_384: b92b883bfd346d916f4a98b40e4e86d2be3cbb22832d9695d3e954b31eeb646a7be0308e4bde98145b5fce370dae8d13
ep_bytes: 60be00004c008dbe0010f4ff5789e58d
timestamp: 2016-03-09 01:13:26

Version Info:

CompanyName: 童心圆
FileDescription: 童心圆记牌器
FileVersion: 0.0.1.161
InternalName: 童心圆记牌器
LegalCopyright: Copyright (C) 作者 2013
OriginalFilename: 同城游掼蛋(宝应掼蛋).exe
ProductName: 童心圆记牌器
ProductVersion: 0.0.1.161
Translation: 0x0009 0x04b0

PUA:Win32/Ymacco also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Strictor.130381
FireEyeGeneric.mg.9a91859cbb54f68d
SkyhighBehavesLike.Win32.ZvuZona.gc
ALYacGen:Variant.Strictor.130381
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Valcaryx.Win32.214
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/SwiftG.8cb0831c
K7GWTrojan ( 0050725b1 )
K7AntiVirusTrojan ( 0050725b1 )
ArcabitTrojan.Strictor.D1FD4D
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.AAuto.A suspicious
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Aauto-9814544-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Strictor.130381
NANO-AntivirusTrojan.Win32.Click3.emvskr
SUPERAntiSpywareTrojan.Agent/Generic
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.13ba8a74
EmsisoftGen:Variant.Strictor.130381 (B)
F-SecureHeuristic.HEUR/AGEN.1322248
DrWebTrojan.Click3.22208
VIPREGen:Variant.Strictor.130381
Trapminemalicious.moderate.ml.score
SophosMal/SwiftG-X
IkarusPUA.AAuto
JiangminAdware.Agent.ypd
VaristW32/Trojan.GCE.gen!Eldorado
AviraHEUR/AGEN.1322248
MAXmalware (ai score=80)
Antiy-AVLGrayWare[AdWare]/Win32.Agent
Kingsoftmalware.kb.b.958
XcitiumMalware@#2iwu3mdc50e3w
MicrosoftPUA:Win32/Ymacco
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Strictor.130381
GoogleDetected
AhnLab-V3Malware/Win32.RL_Generic.R266431
McAfeeGenericRXAA-AA!9A91859CBB54
VBA32BScope.Trojan.Click
Cylanceunsafe
RisingTrojan.Generic!8.C3 (CLOUD)
YandexRiskware.AAuto!1eBc3TyoxJU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Generic
BitDefenderThetaGen:NN.ZexaF.36608.zmKfa4KUdRkG
AVGWin32:Malware-gen
Cybereasonmalicious.37b424
DeepInstinctMALICIOUS

How to remove PUA:Win32/Ymacco?

PUA:Win32/Ymacco removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment