Adware

Should I remove “Win32/Adware.YoBrowser.BT”?

Malware Removal

The Win32/Adware.YoBrowser.BT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.YoBrowser.BT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify browser security settings

How to determine Win32/Adware.YoBrowser.BT?


File Info:

name: E2BCF23EAA5F24B0B6D2.mlw
path: /opt/CAPEv2/storage/binaries/24ed93c5f4a408575486ad02c8bcf7ccac4e56d1acd9964a8a7dd1e296029c01
crc32: B26ACBC1
md5: e2bcf23eaa5f24b0b6d2fa1e22f0144a
sha1: dd9efe99759845c15cd06b4580643178825be2c6
sha256: 24ed93c5f4a408575486ad02c8bcf7ccac4e56d1acd9964a8a7dd1e296029c01
sha512: 67a02cbe7d10235d99b93944c86d00795d43890e8bbb5e83d2e5e5acb81b050d8d9e39e95bb87389cbe9f65235d26063e85a318211eb7b8f69f3012bcd8ae085
ssdeep: 12288:z7blMgEZXl2qI/ZhE5Cd0D67azlqqnHTEknjMxIoYlnlz:z7blHOEqI/EOC67aRq8Imj4Y3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18BB4125652A45172D1B0CAF85E27E05C4E23BE3A2C3C251C36CC5E5E9FA6BA0E11F7D2
sha3_384: 1c0803afe641ebb4c0033bc05eb93382074bf2c5463d532d16f6972b854c07a9e7205ff8efd0fb2c98d5c9bda819599b
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: hectocotylus Setup
FileVersion:
LegalCopyright:
ProductName: hectocotylus
ProductVersion: 1.0
Translation: 0x0000 0x04b0

Win32/Adware.YoBrowser.BT also known as:

LionicRiskware.Win32.Generic.1!c
MicroWorld-eScanGen:Variant.Midie.44267
FireEyeGen:Variant.Midie.44267
ALYacGen:Variant.Midie.44267
CylanceUnsafe
ZillyaAdware.Agent.Win32.137657
SangforTrojan.Win32.GenericKD.40139970
AlibabaAdWare:Win32/YoBrowser.89119953
Cybereasonmalicious.eaa5f2
SymantecPUA.InstallCore
ESET-NOD32a variant of Win32/Adware.YoBrowser.BT
APEXMalicious
Kasperskynot-a-virus:HEUR:AdWare.Win32.Agent.gen
BitDefenderGen:Variant.Midie.44267
NANO-AntivirusTrojan.Win32.YoBrowser.eyfglj
AvastWin32:Adware-gen [Adw]
RisingAdware.YoBrowser!8.E632 (CLOUD)
SophosGeneric PUA NN (PUA)
ComodoApplicUnwnt@#1hltbciu303zj
DrWebTrojan.Zadved.1349
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.hc
EmsisoftGen:Variant.Midie.44267 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1122017
MicrosoftTrojan:Win32/Occamy.C24
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Agent.gen
GDataGen:Variant.Midie.44267
CynetMalicious (score: 99)
AhnLab-V3Adware/Win32.YoBrowser.C2445620
McAfeeRDN/Generic PUP.bwp
MAXmalware (ai score=84)
VBA32Trojan.Zadved
TencentWin32.Adware.Agent.Akfc
YandexPUA.YoBrowser!k9OSHe4U1ik
IkarusPUA.YoBrowser
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/Agent
BitDefenderThetaGen:NN.ZedlaF.34182.Xu8@a0w8hVhi
AVGWin32:Adware-gen [Adw]
PandaPUP/AdwarePlugin
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Win32/Adware.YoBrowser.BT?

Win32/Adware.YoBrowser.BT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment