84,488,480 programs installed

Should I remove Yontoo?

What percent of users and experts removed it?
82% remove it18% keep it
Overall Sentiment
Bad
What do people think about it?
(click star to rate)
How common is it?
Global Rank #13,220
United States Rank #16,104
Reach 0.0232%
Lifespan of installation (until removal)
< 257.74 days
965.31 days >
Average installed length: 507.20 days

Versions

VersionDistribution
2.04 100.00%

Yontoo 2.04

What is Yontoo?

Yontoo is a web browser toolbar and extension. Yontoo collects and stores information about your web browsing habits so they can suggest services or provide advertising. Yontoo is a potentially unwanted application that installs a browser extension to display advertisements that appear to be from Facebook. The program will then install PageRage, a browser extension that modifies the skin layout of Facebook but also displays advertisements which appear to be from Facebook.

About  (from Yontoo Technology)

Yontoo adds a virtual graphic layer over any existing web page. PageRage adds Facebook layouts to your Facebook profile. Yontoo is a browser add-on that horizontally crosses the internet rather than the standard vertical website archive. Yontoo LLC was founded by a small group of people that had worked together on pre...  Read more

Overview

Upon being installed, the software adds a Windows Service which is designed to run continuously in the background. Manually stopping the service has been seen to cause the program to stop functing properly. It adds a background controller service that is set to automatically run. Delaying the start of this service is possible through the service manager. It adds a Browser Helper Object (BHO) to Internet Explorer. The primary executable is named Y2Desktop.Updater.exe. A majority of users end up uninstalling this less than a week of it being installed. The setup package generally installs about 4 files and is usually about 820.4 KB (840,090 bytes). The installed file Y2Desktop.Updater.exe is the auto-update component of the program which is designed to check for software updates and notify and apply them when new versions are discovered.
  • Malware detected in the program
  • Integrates into the web browser
  • Installs a Windows Service
  • Typically distributed through a pay-per-install bundle
  • Injects advertisements unassociated with the underlying web page
  • This program has a poor reputation
  • The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in Yontoo.
Y2Desktop.Updater.exe (24fb8db6d1d55e2c5d0a53dfe48e6af8) has been flagged by the following 10 scanners:
Anti-Virus softwareVersionDetection
AVG 2014.0.3601 Skodna.Generic
Baidu-International 4.0.3.131025 Malware.Win32.Yontoo.40
F-Prot v6.4.7.1.166 W32/ApplCtnX.Y
G Data 13.10.22 Win32.Application.Yontoo
K7 AntiVirus 13.173.9980 Unwanted-Program
Kingsoft AntiVirus 331020.49267 Win32.Troj.WebCake.d.(kcloud)
PC Tools 2013 SecurityRisk.Yontoo!rem
Symantec 10/25/2013 rev. 6 Yontoo
Vba32 AntiVirus 3.12.24.3 TScope.Trojan.MSIL
VIPRE Antivirus 22702 Yontoo (fs)
YontooIEClient.dll (d844fbc9f172cd0c1768d186e043aa5c) has been flagged by the following 11 scanners:
Anti-Virus softwareSoftware versionDetection
Comodo Security 16351 Application.Win32.Yontoo.a
Dr.Web Adware.Plugin.11
Emsisoft Anti-Malware 3.0.0.576 Adware.Win32.Yontoo.AMN (A)
ESET-NOD32 8396 a variant of Win32/Adware.Yontoo.A
Fortinet FortiGate 5.0.43.0 Adware/Yontoo
K7 AntiVirus 9.169.8780 Trojan
K7GW 12.7.0.12 Trojan
PC Tools 9.0.0.2 SecurityRisk.Yontoo!rem
SUPERAntiSpyware 5.6.0.1008 Adware.Yontoo
Symantec 20131.1.0.101 Yontoo
VIPRE Antivirus 18288 Yontoo (v)
sqlite3.exe (8d03b10f0dced524a88a3ff4b370f50d) has been flagged by the following 2 scanners:
Anti-Virus softwareSoftware versionDetection
Antiy-AVL 2.0.3.7 AdWare/Win32.WebCake.gen
Bkav FE 1.3.0.4613 W32.Clodc3a.Trojan.bde5
       View all 23 all detections
Yontoo has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.

Program detailsProgram details

Displayed publisher: Yontoo LLC
URL: www.yontoo.com
Installation folder: C:\Program Files\Yontoo
Uninstaller: C:\Program Files3\TARMAI~1\{889DF~1\Setup.exe /remove /q0
Estimated size: 820.4 KB
Language: English (United States)

Program filesFiles installed by Yontoo 2.04

Program executable:Y2Desktop.Updater.exe (Malware detected)
Name:Y2Desktop.Updater
Path:C:\Program Files\Yontoo\Y2Desktop.Updater.exe
MD5:24fb8db6d1d55e2c5d0a53dfe48e6af8
Additional files:
  • (Malware detected) YontooIEClient.dll - Yontoo Runtime
  • OptChrome.exe
  • (Malware detected) sqlite3.exe
  • (Malware detected) Y2Desktop.Updater.exe (by Microsoft) - Y2Desktop.Updater

Program behaviorsBehaviors exhibited

Internet Explorer BHO
  • YontooIEClient.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'Yontoo' with the class of {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} (Yontoo Layers).
Service
  • Y2Desktop.Updater.exe runs as a service named 'Yontoo Desktop Updater' (Yontoo Desktop Updater) "Provides limited updating assistance for Yontoo Desktop".

Program resource utilizationResource utilization averages

Y2Desktop.Updater.exe
Memory:13.36 MB
21.09 MB average
Total CPU:0.0042251088%
0.031193% average
Kernel CPU:0.00247864%
0.016088% average
User CPU:0.00174647%
0.015104% average
CPU cycles/sec:14,481
8,062,084 average
I/O reads/min:224 Bytes
435.61 KB average
I/O writes/min:128 Bytes
105.02 KB average

How do I remove Yontoo?

You can uninstall Yontoo from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program Yontoo 2.04, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove Yontoo.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by Yontoo 2.04 you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome

OS VERSIONS
Win 7 (SP1) 68%
Win XP 0%
 
HOW IT RUNS
Windows Service? Yes
(Installs a service)
 
USER ACTIONS
Uninstall it 82%
Keep it 18%

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 75.27%
Windows 10 14.66%
Windows XP 5.03%
Windows Vista 5.03%
Which OS releases does it run on?
Windows 7 Home Premium 49.67%
Windows 7 Ultimate 15.60%
Windows 7 Professional 7.25%
Windows 8 5.05%
Microsoft Windows XP 4.84%
Windows Vista Home Premiu... 3.52%

Distribution by countryGeography

30.84% of installs come from the United States
Which countries install it?
  United States 30.84%
  Germany 10.22%
  United Kingdom 5.70%
  Italy 4.13%
  Canada 3.73%
  France 3.34%
  Netherlands 3.14%
  Australia 2.75%
  Spain 2.36%
  India 2.36%
  Mexico 2.36%
  Japan 1.57%
  Saudi Arabia 1.38%
  Sweden 1.38%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Hewlett-Packard 30.82%
Dell 19.81%
Acer 17.30%
Toshiba 9.43%
ASUS 7.55%
Samsung 5.97%
Lenovo 4.40%
Sony 1.57%
GIGABYTE 1.26%
Alienware 0.94%
Medion 0.94%
Common models
HP Pavilion dv6 Notebook ... 5.33%
Dell Inspiron N5110 4.14%
HP Pavilion g6 Notebook P... 3.55%
HP 2000 Notebook PC 2.96%
Dell Inspiron 560 2.37%
HP G60 Notebook PC 2.37%

About Yontoo Technology

Yontoo, a subsidiary/alias of ad-hijacker Sambreel, is a publisher of ad-supported web browser extensions designed to inject and display advertisements within the browser.
Publisher URL: www.yontoo.com

commentsComments

user comment
No one has commented yet. Help others learn more about this software, share your comments.