Should I block it?
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization
Additional versions
Relationships
PE file structure |
Show functions |
Import table
mscoree.dll
DllMain
YontooDesktop.exe
Yontoo Desktop by Yontoo LLC (Signed)
Version: | 1.0.4884.27585 |
MD5: | 1a6615bbc61ddfa4deca9eb7d0497c88 |
SHA1: | acf9e9d055517b6571fb5ef39869632f5c85a2d5 |
SHA256: | e8185d652aca66968f0e2d7d37a7f11825f581e419a0bd02ab2ba9e1a08641ad |
Warning 5 antivirus scanners has detected malware.
What is YontooDesktop.exe?
Yontoo Runtime for Yontoo is a web browser toolbar and extension. Yontoo collects and stores information about your web browsing habits so they can suggest services or provide advertising. The plugin commonly displays ads and deals from affiliated merchants and clicking on such links some times ends up in installing other unwanted browser add-ons or even malware.
About YontooDesktop.exe (from Yontoo LLC)
“Yontoo is a browser add-on that horizontally crosses the internet rather than the standard vertical website archive. Yontoo LLC was founded by a small group of people that had worked together on previ”
Details
File name: | yontoodesktop.exe |
Publisher: | Yontoo LLC |
Product name: | Yontoo Desktop |
Typical file path: | C:\users\user\appdata\roaming\yontoo\yontoodesktop.exe |
File version: | 1.0.4884.27585 |
Size: | 46.28 KB (47,392 bytes) |
Build date: | 5/17/2013 6:19 AM |
Certificate |
Issued to: | Yontoo LLC |
Authority (CA): | VeriSign |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | No |
Code language: | Microsoft Visual C# / Basic .NET |
.NET CLR: | Yes |
.NET NGENed: | No |
More details
Behaviors
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'Yontoo Desktop' → "C:\users\user\appdata\Roaming\Yontoo\YontooDesktop.exe"
Malware detections
Based on 40+ industry antivirus scanners, 5 of them detected the following malware.
Antivirus engine | Engine version | Detection |
AVG |
13.0.0.3169 |
AdInject.Yontoo |
ESET NOD32 |
7.8836 |
a variant of MSIL/WebCake.B |
PC Tools |
9.0.0.2 |
SecurityRisk.Yontoo!rem |
Symantec |
20131.1.5.61 |
Yontoo |
VIPRE Antivirus |
21774 |
Yontoo (v) |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.05324350% | |
Kernel CPU: | 0.03894952% | |
User CPU: | 0.01429397% | |
Memory |
Private (maximum): | 32.49 MB | |
Private (minimum): | 24.07 MB | |
Process properties
Platform: | 64-bit |
Command line: | "C:\users\user\appdata\roaming\yontoo\yontoodesktop.exe" |
Owner: | User |
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate |
37.50% |
|
Windows 8 Pro |
20.83% |
|
Microsoft Windows XP |
16.67% |
|
Windows 8 |
8.33% |
|
Windows 7 Home Premium |
8.33% |
|
Windows 7 Professional |
8.33% |
|
Distribution by country
United Kingdom installs about 16.67% of Yontoo Desktop.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Acer |
26.09% |
|
Hewlett-Packard |
17.39% |
|
Dell |
17.39% |
|
Lenovo |
17.39% |
|
Samsung |
8.70% |
|
GIGABYTE |
8.70% |
|
American Megatrends |
4.35% |
|