SOSVirus » news » PUP.Optional.Yontoo

PUP.Optional.Yontoo

Yontoo is a software usually installed without your knowledge with the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified : 10/05/2013.

Features

– It belongs to a family of PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– A toolbar is an additional internet browser bar.
– Vendor : PUP.Optional

Main Actions

– It installs a plugin of the browser Google Chrome (G2),
– It installs a program of extension for browser Mozilla Firefox (M2),
– It installs a plugin of the browser Mozilla Firefox (P2),
– It is installed as a BHO (Browser Helper Object) of internet browser (O2),
– It installs as a process launched at startup of the system (RP),
– It installs as a program (O42),
– It creates to many registry keys ‘Software’,
– It creates additional folders (O43),
– It installs a process of variable size to the level of the system folders (O44),
– It moved to the Windows prefetcher folder (O45),
– It creates a registry StartupReg key (O53),
– It creates multiple files users (O61),

– (.Yontoo LLC – Yontoo Desktop.) — C:UsersPc1AppDataRoamingYontooYontooDesktop.exe
– (.Microsoft – Y2Desktop.Updater.) — C:Program Files (x86)YontooY2Desktop.Updater.exe
G2 – GCE: Preference Yontoo v.1.0.3 (Activé )
M2 – MFEP: prefs.js [] Yontoo v1.20.02 (..)
O2 – BHO: Yontoo Layers – {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} (.Yontoo LLC.) — C:Program FilesYontoo Layers RuntimeYontooIEClient.dll
O4 – HKCU..Run: C:Documents and SettingsCoolmanApplication DataYontooYontooDesktop.exe (.not file.)
O4 – HKUSS-1-5-21-1333877253-4193380580-4002807941-1007..Run: C:Documents and SettingsCoolmanApplication DataYontooYontooDesktop.exe (.not file.)
O42 – Logiciel: Yontoo 2.053 – (.Yontoo LLC.) — {889DF117-14D1-44EE-9F31-C5FB5D47F68B}
O43 – CFD: 15/05/2013 – 14:00:59 – —-D C:Program FilesYontoo
O43 – CFD: 15/05/2013 – 14:01:48 – —-D C:Documents and SettingsCoolmanApplication DataYontoo
O45 – LFCP: – 15/05/2013 – 13:00:54 —A- – C:WINDOWSPrefetchYONTOO-C4.EXE-11DB6439.pf
O45 – LFCP: – 15/05/2013 – 13:00:55 —A- – C:WINDOWSPrefetchYONTOO-C4-10C0.EXE-3510B2BC.pf
O45 – LFCP: – 15/05/2013 – 13:01:11 —A- – C:WINDOWSPrefetchYONTOODESKTOP.EXE-1CAF6818.pf
O53 – SMSR:HKLM…startupregYontoo Desktop . (…) — C:UsersCoolmanAppDataRoamingYontooYontooDesktop.exe
O61 – LFC: 15/05/2013 – 13:01:24 —A- C:Documents and SettingsCoolmanApplication DataYontoodatDesktop.OS.dll
O61 – LFC: 15/05/2013 – 13:01:28 —A- C:Documents and SettingsCoolmanApplication DataYontoodatDesktop.OS.Plugin.dll
O61 – LFC: 15/05/2013 – 13:01:29 —A- C:Documents and SettingsCoolmanApplication DataYontooPlugIns.cache
O61 – LFC: 15/05/2013 – 13:01:30 —A- C:Documents and SettingsCoolmanApplication DataYontoodatHealthMonitor.dat
O61 – LFC: 15/05/2013 – 13:01:30 —A- C:Documents and SettingsCoolmanApplication DataYontoodatHeartBeat.dat
O61 – LFC: 15/05/2013 – 18:34:00 —A- C:Documents and SettingsCoolmanLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc1.0.3_0back.js
O61 – LFC: 15/05/2013 – 18:34:01 —A- C:Documents and SettingsCoolmanLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc1.0.3_0background.html
O61 – LFC: 15/05/2013 – 18:34:01 —A- C:Documents and SettingsCoolmanLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc1.0.3_0manifest.json
O61 – LFC: 15/05/2013 – 18:34:01 —A- C:Documents and SettingsCoolmanLocal SettingsApplication DataGoogleChromeUser DataDefaultExtensionsniapdbllcanepiiimjjndipklodoedlc1.0.3_0yl.js
O61 – LFC: 16/05/2013 – 11:01:22 —A- C:Documents and SettingsCoolmanLocal SettingsApplication DataGoogleChromeUser DataDefaultLocal Storagechrome-extension_niapdbllcanepiiimjjndipklodoedlc_0.localstorage
O61 – LFC: 16/05/2013 – 11:01:22 —A- C:Documents and SettingsCoolmanLocal SettingsApplication DataGoogleChromeUser DataDefaultLocal Storagechrome-extension_niapdbllcanepiiimjjndipklodoedlc_0.localstorage-journal
(.Yontoo LLC – Yontoo Runtime.) — C:UsersCoolmanAppDataLocalTempYontooIEClient.dll
(.Yontoo LLC – Installer.) — C:UsersCoolmanAppDataLocalTempYontooSetup-Silent.exe
(.Yontoo LLC – Installer.) — C:UsersCoolmanAppDataLocalTempYontooSetup-S.exe

:Yontoo Desktop

C:Program FilesYontoo Layers
C:Program FilesYontoo Layers Client
C:Program FilesYontoo Layers Runtime
C:Program Filesyontoo
C:Documents and SettingsCoolmanApplication Datayontoo
C:Documents and SettingsCoolmanApplication DataMozillaFirefoxProfiles6andx3ch.defaultExtensionsplugin@yontoo.com
SR – | Auto 01/05/2013 23552 | (Yontoo Desktop Updater) . (.Microsoft.) – C:Program FilesYontooY2Desktop.Updater.exe

Alias

PUP.Optional.Yontoo.A
Adware.Yontoo

Remove Software

– Remove software in Windows Configuration Panel,

Remove with ZHPcleaner

Diagnose with ZHPDiag

1 Vote2 Votes3 Votes4 Votes5 Votes (1 votes, average: 5.00 out of 5)
SOSVirusLoading...

Leave a Comment