Yontoo

Yontoo

Known Toolbar

by Yontoo Technology, Inc.

What is Yontoo?

Yontoo is software application developed by Yontoo Technology, Inc.. It is most commonly found on computers running Windows 7 with nearly 73.75% of installations running this operating system. Yontoo's installer is typically 823.00 KB in size and installs around 11 files. The most common release is 1.10.04 with 31.49% of all installations currently using this version.

Yontoo is most popular in the United States with 39.53% of installations residing in this country.

About Yontoo?

Yontoo is a browser extension and toolbar that gathers user web browsing data in order to offer personalized services and advertising suggestions. This potentially unwanted application is known for installing browser extensions that display advertisements resembling those from Facebook. Additionally, Yontoo installs PageRage, a browser extension that alters the appearance of Facebook with customized skins while also displaying advertisements resembling those from the social media platform.

Multiple virus scanners have detected malware in Yontoo.

YontooIEClient.dll (MD5: abd9b86eada05955cd1a82ae70de4fd4) has been flagged by 12 scanners:
Scanner Software Result
Comodo Security Application.Win32.Yontoo.a
Dr.Web Adware.Plugin.11
Emsisoft Anti-Malware Adware.Win32.Yontoo.AMN (A)
eSafe Win32.Trojan
ESET-NOD32 a variant of Win32/Adware.Yontoo.A
PC Tools SecurityRisk.Yontoo!rem
SUPERAntiSpyware Adware.Yontoo
Symantec Yontoo
TrendMicro-HouseCall TROJ_GEN.RCBH1JQ
VIPRE Antivirus Yontoo (v)
Antiy-AVL AdWare/Win32.WebCake.gen
Bkav FE W32.Clodc3a.Trojan.bde5
sqlite3.exe (MD5: 8d03b10f0dced524a88a3ff4b370f50d) has been flagged by 2 scanners:
Scanner Software Result
Antiy-AVL AdWare/Win32.WebCake.gen
Bkav FE W32.Clodc3a.Trojan.bde5
YontooIEClient_2.dll (MD5: fd05b3fcabf42ca72f7f166a6e0c62c7) has been flagged by 9 scanners:
Scanner Software Result
Agnitum Outpost Adware.Yontoo!uZbtZZsvrqI
Avira AntiVir Adware/Yontoo.A.9
Comodo Security Application.Win32.Yontoo.a
Dr.Web Adware.Siggen.24249
Emsisoft Anti-Malware Adware.Win32.Yontoo.A!A2
ESET-NOD32 Win32/Adware.Yontoo.A
Fortinet FortiGate Riskware/Yontoo
Vba32 AntiVirus Adware.Yontoo.a
VIPRE Antivirus Yontoo (v)
Y2Desktop.Updater.exe (MD5: 24fb8db6d1d55e2c5d0a53dfe48e6af8) has been flagged by 19 scanners:
Scanner Software Result
AVG Skodna.Generic
Baidu-International Malware.Win32.Yontoo.40
F-Prot W32/ApplCtnX.Y
G Data Win32.Application.Yontoo
K7 AntiVirus Unwanted-Program
Kingsoft AntiVirus Win32.Troj.WebCake.d.(kcloud)
PC Tools SecurityRisk.Yontoo!rem
Symantec Yontoo
Vba32 AntiVirus TScope.Trojan.MSIL
VIPRE Antivirus Yontoo (fs)
Comodo Security Application.Win32.Yontoo.a
Dr.Web Adware.Plugin.11
Emsisoft Anti-Malware Adware.Win32.Yontoo.AMN (A)
eSafe Win32.Trojan
ESET-NOD32 a variant of Win32/Adware.Yontoo.A
SUPERAntiSpyware Adware.Yontoo
TrendMicro-HouseCall TROJ_GEN.RCBH1JQ
Antiy-AVL AdWare/Win32.WebCake.gen
Bkav FE W32.Clodc3a.Trojan.bde5

Software Behaviors

Services:
  • Y2Desktop.Updater.exe runs as a service named 'Yontoo Desktop Updater' (Yontoo Desktop Updater) "Provides limited updating assistance for Yontoo Desktop".

Software Details

URL:
https://www.yontoo.com
Support:
Installation path:
C:\Program Files\Yontoo
Uninstaller:
C:\Program Files3\TARMAI~1\{889DF~1\Setup.exe /remove /q0
Size:
823.00 KB
Language:
English

Yontoo Executable Details

Primary executable:
OptChrome.exe
Name:
Yontoo
Path:
C:\Program Files\Yontoo\OptChrome.exe
MD5:
e014fa47c8e1ebd80f114ff87934f907
SHA-1:
SHA-256:
Files installed by Yontoo
File Type Filename MD5
EXE
e014fa47c8e1ebd80f114ff87934f907
DLL
abd9b86eada05955cd1a82ae70de4fd4
EXE
75fc245b31a2559f3ab0fe79f9034df1
CRX
f158b5d37aa5d7fb3092c59c8b136ae5
EXE
8d03b10f0dced524a88a3ff4b370f50d
DLL
fd05b3fcabf42ca72f7f166a6e0c62c7
EXE
24fb8db6d1d55e2c5d0a53dfe48e6af8
EXE
ede5aeec71378f6fb088088ae977b107
EXE
fcb4d8a3a03e99f085eacd16ef908a37
EXE
88eb56e13099b99cbd5e028f2ea3c327