Home Malware Programs Potentially Unwanted Programs (PUPs) Y2Go

Y2Go

Posted: April 17, 2017

Threat Metric

Ranking: 19,978
Threat Level: 1/10
Infected PCs: 1,923
First Seen: April 17, 2017
Last Seen: December 25, 2024
OS(es) Affected: Windows

Y2Go is a potentially unwanted program that may offer methods for monitoring or viewing web traffic. The Y2Go may be offered as an add-on component for popular web browser programs where it may be somewhat intrusive with its actions and display of pop-up features or even advertisements. In most cases, Y2Go is loaded due to the installation of third party apps, freeware or bundled apps downloaded from the Internet.

The monitoring actions of Y2Go may posse somewhat questionable action for many computer users. Due to the uncertainty of Y2Go’s actions, some computer users will want to eliminate the Y2Go program and discontinue use of its offered features and functions. Those wishing to discontinue use of Y2Go may do so by either using an antimalware tool or going through the Internet settings of popular web browser programs.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Local\MicrosoftHelper\bin\UrlHandler.exe File name: UrlHandler.exe
Size: 346.59 KB (346592 bytes)
MD5: 6493f607c63b6715730b1b75fa6bfaa5
Detection count: 124
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\MicrosoftHelper\bin\UrlHandler.exe
Group: Malware file
Last Updated: March 1, 2021
%LOCALAPPDATA%\MicrosoftHelper\bin\Y2Go.exe File name: Y2Go.exe
Size: 2.33 MB (2330592 bytes)
MD5: 246c1fd08f967caba7f9c38c1e925dfd
Detection count: 103
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\MicrosoftHelper\bin
Group: Malware file
Last Updated: June 30, 2018
%LOCALAPPDATA%\OneDrive\bin\OneDrive.exe File name: OneDrive.exe
Size: 2.78 MB (2788184 bytes)
MD5: d151c4a957af99f3bb658b2b05193cc2
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\OneDrive\bin
Group: Malware file
Last Updated: April 20, 2020
%LOCALAPPDATA%\OneDriveUpdater\updater.exe File name: updater.exe
Size: 1.97 MB (1976152 bytes)
MD5: 749b9364aea7048b6665bb492a29c67e
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\OneDriveUpdater
Group: Malware file
Last Updated: April 20, 2020
%LOCALAPPDATA%\OneDrive\bin\pt.exe File name: pt.exe
Size: 2 MB (2008408 bytes)
MD5: 4e62c791aaeb26f0a061378447fc011b
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\OneDrive\bin
Group: Malware file
Last Updated: March 27, 2021
C:\Users\<username>\AppData\Local\MicrosoftHelper\bin\WebControl.exe File name: WebControl.exe
Size: 367.07 KB (367072 bytes)
MD5: f7460a8c3c6a68831794b53f8c00f792
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\MicrosoftHelper\bin\WebControl.exe
Group: Malware file
Last Updated: March 1, 2021
%LOCALAPPDATA%\OneDriveUpdater\taskutil.exe File name: taskutil.exe
Size: 264.53 KB (264536 bytes)
MD5: 6c6ff6732abe44ad6435885e18f568bf
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\OneDriveUpdater
Group: Malware file
Last Updated: October 27, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Y2GoSoftware\Y2GoHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Y2Go

Additional Information

The following directories were created:
%LOCALAPPDATA%\MicrosoftHelper%LOCALAPPDATA%\OneDriveUpdater%PROGRAMFILES%\Y2Go%PROGRAMFILES(x86)%\Y2Go%WINDIR%\System32\Tasks\Y2Go
Loading...