Adware

Adware.Agent.YBR removal tips

Malware Removal

The Adware.Agent.YBR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Agent.YBR virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Harvests information related to installed mail clients

How to determine Adware.Agent.YBR?


File Info:

crc32: 2630E19F
md5: 01ec69abedc6074b8061b2684b293177
name: 01EC69ABEDC6074B8061B2684B293177.mlw
sha1: bbbed1c2af243885077429b7837947030bb1d54f
sha256: d9f03016c15746ed597c5e4e9eabe39c8cb421784fd018f57553b6f339401faa
sha512: 10e568ea2abd04151e2b2b4fb18f334a0deefd3e866964cbac3ae41ef2a4eb74d8bc498e4df7b6bf9857c4062a953e42165c231e2a8036a9d2a37de449a34849
ssdeep: 12288:8adLWD7888888888888W88888888888qpSpPiHz5iGNn07c3Udc1RNzRq7YAVkTq:bBWgpSp6T5j0OlqmuBYKq7I6Khyk0ti
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion: 22.11.56
CompanyName: fCtuBv3XTjBNqOWthfro
Comments: This installation was built with Inno Setup.
ProductName: fCtuBv3XTjBNqOWthfro
ProductVersion: 22.11.56
FileDescription: fCtuBv3XTjBNqOWthfro
Translation: 0x0000 0x04b0

Adware.Agent.YBR also known as:

K7AntiVirusTrojan ( 005301de1 )
LionicAdware.Win32.ExtInstaller.2!c
Elasticmalicious (high confidence)
DrWebTrojan.BPlug.3331
CynetMalicious (score: 99)
ALYacAdware.Agent.YBR
CylanceUnsafe
SangforAdware.Win32.ExtInstaller.gen
AlibabaAdWare:Win32/ExtInstaller.a032be5f
K7GWTrojan ( 005301de1 )
Cybereasonmalicious.bedc60
CyrenW32/Zusy.FM.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
Kasperskynot-a-virus:HEUR:AdWare.Win32.ExtInstaller.gen
BitDefenderGen:Variant.Mikey.82377
NANO-AntivirusTrojan.Win32.ExtenBro.fdturf
MicroWorld-eScanGen:Variant.Mikey.82377
TencentWin32.Trojan.Razy.Fse
SophosGeneric PUA LL (PUA)
ComodoApplicUnwnt@#3sz6unryyyua2
F-SecureHeuristic.HEUR/AGEN.1109568
BitDefenderThetaGen:NN.ZedlaF.34170.Mu8@ayhvKmgO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.FileTour.bc
FireEyeGen:Variant.Mikey.82377
EmsisoftGen:Variant.Mikey.82377 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1109568
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitAdware.Agent.YBR
SUPERAntiSpywareAdware.ExtenBro/Variant
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.ExtInstaller.gen
GDataAdware.Agent.YBR
McAfeePUP-GZB
MAXmalware (ai score=99)
VBA32Adware.ExtInstaller
MalwarebytesAdware.ExtenBro
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PIU21
YandexTrojan.GenAsa!+YqEKEgb04c
IkarusTrojan.Win32.Extenbro
FortinetAdware/Generic
AVGWin32:MalwareX-gen [Trj]

How to remove Adware.Agent.YBR?

Adware.Agent.YBR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment