<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Workstation Pro 16.1 identified as Trojan Win32/Ymacco.AA32 and Win32/Ymacco.AA0F by WindowsDefe in VMware Workstation Pro Discussions</title>
    <link>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826699#M168569</link>
    <description>&lt;P&gt;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/5472776"&gt;@jmfoottit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that VMTN is a user community forum, and not an official method of communicating with anyone in particular at VMware.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Feb 2021 09:00:08 GMT</pubDate>
    <dc:creator>scott28tt</dc:creator>
    <dc:date>2021-02-01T09:00:08Z</dc:date>
    <item>
      <title>Workstation Pro 16.1 identified as Trojan Win32/Ymacco.AA32 and Win32/Ymacco.AA0F by WindowsDefender</title>
      <link>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826576#M168544</link>
      <description>&lt;P&gt;Hello, yesterday I downloaded and installed Workstation Pro from the official VMWare website and activated the free trial period.&lt;/P&gt;&lt;P&gt;Today Windows Defender, while doing a full system scan, flagged as trojan some files that were in the VMware installation directory (InstallerCache, SetupBrowser and some .cab files, but also EFI32.ROM and 1e1d33.msi). I also have Malwarebytes installed and it didn't flagged any suspicious file. A subsequent scan with Microsoft Safety scanner also showed no infected files.&lt;/P&gt;&lt;P&gt;Is it possible that those files were detected as false positives or should I start to worry about the safety of my system?&lt;/P&gt;&lt;P&gt;(I can add photos with the full scan results if that can help)&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jan 2021 16:18:52 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826576#M168544</guid>
      <dc:creator>intertesting</dc:creator>
      <dc:date>2021-01-31T16:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Workstation Pro 16.1 identified as Trojan Win32/Ymacco.AA32 and Win32/Ymacco.AA0F by WindowsDefe</title>
      <link>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826672#M168561</link>
      <description>&lt;P&gt;Hi! I have the same issue.&lt;/P&gt;&lt;P&gt;Detection time(UTC time): 1/30/2021 12:00:10 PM Malware file path: containerfile:_C:\Program Files (x86)\Common Files\VMware\InstallerCache\{95096479-66A1-454B-9378-234DF3B31727}.msi;containerfile:_C:\Program Files (x86)\VMware\VMware Workstation\x64\EFI32.ROM;containerfile:_C:\Windows\Installer\c03c8c.msi;file:_C:\Program Files (x86)\Common Files\VMware\InstallerCache\{95096479-66A1-454B-9378-234DF3B31727}.msi-&amp;gt;Workstation.cab-&amp;gt;_EFI32.ROM-&amp;gt;{20BC8AC9-94D1-4208-AB28-5D673FD73486}-&amp;gt;NvmExpressDxe;file:_C:\Program Files (x86)\VMware\VMware Workstation\x64\EFI32.ROM-&amp;gt;{20BC8AC9-&lt;/P&gt;&lt;P&gt;Remediation action: NoAction&lt;BR /&gt;Action status: Succeeded&lt;/P&gt;&lt;P&gt;Checked the sha256&amp;nbsp;4e96fd7b6290fc29d7a0095fadb0fb36daa54c767530d91c55f70c38d88d4747 against virustotal and 26/70 tells malware.&lt;/P&gt;&lt;P&gt;Someone who can tell anything?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 06:41:35 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826672#M168561</guid>
      <dc:creator>tjsk</dc:creator>
      <dc:date>2021-02-01T06:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Workstation Pro 16.1 identified as Trojan Win32/Ymacco.AA32 and Win32/Ymacco.AA0F by WindowsDefe</title>
      <link>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826692#M168567</link>
      <description>&lt;P&gt;I have installed vmware workstation pro on a fresh install of 20H2 win10 pro. I get the same Threat blocked..... VMWare what's the deal here please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 08:26:41 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826692#M168567</guid>
      <dc:creator>jmfoottit</dc:creator>
      <dc:date>2021-02-01T08:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Workstation Pro 16.1 identified as Trojan Win32/Ymacco.AA32 and Win32/Ymacco.AA0F by WindowsDefe</title>
      <link>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826699#M168569</link>
      <description>&lt;P&gt;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/5472776"&gt;@jmfoottit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that VMTN is a user community forum, and not an official method of communicating with anyone in particular at VMware.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 09:00:08 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826699#M168569</guid>
      <dc:creator>scott28tt</dc:creator>
      <dc:date>2021-02-01T09:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Workstation Pro 16.1 identified as Trojan Win32/Ymacco.AA32 and Win32/Ymacco.AA0F by WindowsDefe</title>
      <link>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826840#M168580</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/274885"&gt;@scott28tt&lt;/a&gt;&amp;nbsp;, sorry for posting this help request here but I did not know where else to put it in order to get some help from people who definitely know VMware products more than me...&lt;/P&gt;&lt;P&gt;That being said, how could I contact someone from VMware in order to get some help to resolve this issue (or, hopefully, just a confirmation that Defender is seeing these files as a false positive)?&lt;/P&gt;&lt;P&gt;Also, has anybody who has had my same issue found a solution? I tried to scan my system again with both Malwarebytes and Kaspesky and they did not find any thread, but you can never be too sure I guess...&lt;/P&gt;&lt;P&gt;also&amp;nbsp;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/129410"&gt;@tjsk&lt;/a&gt;&amp;nbsp;did you managed to find a solution to your problem?&lt;/P&gt;&lt;P&gt;Thanks to anybody who will reply and try to help!&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 19:20:07 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826840#M168580</guid>
      <dc:creator>intertesting</dc:creator>
      <dc:date>2021-02-01T19:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Workstation Pro 16.1 identified as Trojan Win32/Ymacco.AA32 and Win32/Ymacco.AA0F by WindowsDefe</title>
      <link>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826856#M168581</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case Windows Defender found this. Not sure if it's a false positive or not but managed to remove it with Defender and subsequently did 2 more complete scans and seems to be gone now&lt;/P&gt;&lt;P&gt;Program:Win32/Uwasson.A!ml&lt;/P&gt;&lt;P&gt;Affected items:&lt;/P&gt;&lt;P&gt;containerfile: C:\Program Files (x86)\Common Files\VMware\InstallerCache\{F838A98A-9A53-4983-9D1E-134EC757A162}.msi&lt;/P&gt;&lt;P&gt;containerfile: C:\Program Files (x86)\VMware\VMware Workstation\x64\EFI32.ROM&lt;/P&gt;&lt;P&gt;containerfile: C:\Users\username\AppData\Local\VMware\vmware-download-0454\cdstmp_ws-windows_16.1.0_17198959\VMware-workstation-16.1.0-17198959.exe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, there are 4 folders with this DIFXAPI.dll file in the Temp directory and these files/folders can't be renamed or deleted even with Admin rights:&lt;/P&gt;&lt;P&gt;1. HICD752.tmp.dir&lt;/P&gt;&lt;P&gt;2. OWAA62C.tmp.dir&lt;/P&gt;&lt;P&gt;3. WGIC9A.tmp.dir&lt;/P&gt;&lt;P&gt;4. ZMH98A2.tmp.dir&lt;/P&gt;&lt;P&gt;Seems as if the installer has been compromised?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 20:27:07 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826856#M168581</guid>
      <dc:creator>GaryF_MAC</dc:creator>
      <dc:date>2021-02-01T20:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Workstation Pro 16.1 identified as Trojan Win32/Ymacco.AA32 and Win32/Ymacco.AA0F by WindowsDefe</title>
      <link>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826860#M168582</link>
      <description>&lt;P&gt;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/5472657"&gt;@intertesting&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No need to apologise, I was just making you aware so you have realistic expectations.&lt;/P&gt;
&lt;P&gt;The one person I am aware of at VMware who might be able to help is&amp;nbsp;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/767659"&gt;@Mikero&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 20:57:33 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826860#M168582</guid>
      <dc:creator>scott28tt</dc:creator>
      <dc:date>2021-02-01T20:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Workstation Pro 16.1 identified as Trojan Win32/Ymacco.AA32 and Win32/Ymacco.AA0F by WindowsDefe</title>
      <link>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826928#M168584</link>
      <description>&lt;P&gt;Windows defender clean up everything &lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/5472657"&gt;@intertesting&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My concern is that this is something like solarwinds. And hoped someone from vmware could explain why some many antimalware take the installer of the workstaition like malware?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 06:10:38 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-Workstation-Pro/Workstation-Pro-16-1-identified-as-Trojan-Win32-Ymacco-AA32-and/m-p/2826928#M168584</guid>
      <dc:creator>tjsk</dc:creator>
      <dc:date>2021-02-02T06:10:38Z</dc:date>
    </item>
  </channel>
</rss>

