Adware

How to remove “Adware:Win32/Yobrowser!mclg”?

Malware Removal

The Adware:Win32/Yobrowser!mclg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware:Win32/Yobrowser!mclg virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Adware:Win32/Yobrowser!mclg?


File Info:

name: B111EBF320020821FBDF.mlw
path: /opt/CAPEv2/storage/binaries/350fb754f8a5877565afeb802d00b48f31d317df68e4c302987568bfc2a85701
crc32: C6CE865F
md5: b111ebf320020821fbdf39b61c46eb44
sha1: db7845022b7dafa5c192f3f12549aaa18d72b8b4
sha256: 350fb754f8a5877565afeb802d00b48f31d317df68e4c302987568bfc2a85701
sha512: 4cd36f1ce818bf79018e9d4fa95710bcd81b7eef9d05fc12a1d02c778d6480564a70546f7d02b14a4cd43a0b36e05dca95f5a1a9785ad0c2220e7ae53e577e72
ssdeep: 24576:Rlh1fvdnfybOhNlpTMhKhnUhsOLWtD2Zr3eKzUeBFExRJVp:fdnftNjThnXptD2Zr3DYOiV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17845F054BD0CC85BEF900974F818C6F0111A4CE9B89436AB169FFE2FF9B276065DCA19
sha3_384: cebdfb8ac86266b28a57971d9df87e069b95cf03391c6be4567520b5385b573de3c1521a11640d0f875500791b77511c
ep_bytes: 60be002056008dbe00f0e9ff57eb0b90
timestamp: 2020-07-05 19:59:39

Version Info:

FileVersion: 0.0.1.0
ProductVersion: 1.0.1.5
OriginalFilename: HHBP[TYPE1].exe
InternalName: HHBP[TYPE1].exe
FileDescription: Bypass
CompanyName: HHBP
LegalCopyright: HHBP 2020
ProductName: Bypass GAMELOOP
Translation: 0x0809 0x04b0

Adware:Win32/Yobrowser!mclg also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.37303638
ClamAVWin.Malware.Dabw-7609398-0
ALYacTrojan.GenericKD.37303638
SangforVirus.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaPacked:Win32/AuItInj.831afd67
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.AutoIt.TO
APEXMalicious
BitDefenderTrojan.GenericKD.37303638
AvastWin32:Trojan-gen
EmsisoftTrojan.GenericKD.37303638 (B)
DrWebTrojan.Packed2.43189
VIPRETrojan.GenericKD.37303638
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
Trapminemalicious.moderate.ml.score
FireEyeTrojan.GenericKD.37303638
SophosMal/AuItInj-C
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.37303638
JiangminTrojan/Blocker.idi
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D2393556
ViRobotTrojan.Win32.Agent.1789440[UPX]
MicrosoftAdware:Win32/Yobrowser!mclg
GoogleDetected
McAfeeArtemis!B111EBF32002
VBA32TrojanDownloader.Agent
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:xshTHTyRIu8dj2Nv6GLueg)
IkarusTrojan.Krypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.35B9E4!tr
BitDefenderThetaGen:NN.ZexaF.36348.mnKfaqA07oci
AVGWin32:Trojan-gen
Cybereasonmalicious.22b7da
DeepInstinctMALICIOUS

How to remove Adware:Win32/Yobrowser!mclg?

Adware:Win32/Yobrowser!mclg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment