Should I block it?
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization
Additional versions
Relationships
YontooDesktop.exe
Yontoo Desktop by Yontoo LLC (Signed)
Version: | 1.0.4780.29731 |
MD5: | 0c85b24c059c0614aa506d15c9a7978d |
SHA1: | 77603c73753651529c22cf2ecb5b977fcd4d7e35 |
SHA256: | d0a66f2b3a72065f1ed323abec37ea02433b7cd566d01e6e8dc1e032c81bbd4d |
Warning 4 antivirus scanners has detected malware.
What is YontooDesktop.exe?
Yontoo Runtime for Yontoo is a web browser toolbar and extension. Yontoo collects and stores information about your web browsing habits so they can suggest services or provide advertising. The plugin commonly displays ads and deals from affiliated merchants and clicking on such links some times ends up in installing other unwanted browser add-ons or even malware.
About YontooDesktop.exe (from Yontoo LLC)
“Yontoo is a browser add-on that horizontally crosses the internet rather than the standard vertical website archive. Yontoo LLC was founded by a small group of people that had worked together on previ”
Details
File name: | yontoodesktop.exe |
Publisher: | Yontoo LLC |
Product name: | Yontoo Desktop |
Typical file path: | C:\users\user\appdata\roaming\yontoo\yontoodesktop.exe |
File version: | 1.0.4780.29731 |
Size: | 41.78 KB (42,784 bytes) |
Certificate |
Issued to: | Yontoo LLC |
Authority (CA): | VeriSign |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | No |
Code language: | Microsoft Visual C# / Basic .NET |
.NET CLR: | Yes |
.NET NGENed: | No |
More details
Behaviors
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'Yontoo Desktop' → "C:\users\user\appdata\Roaming\Yontoo\YontooDesktop.exe"
Malware detections
Based on 40+ industry antivirus scanners, 4 of them detected the following malware.
Antivirus engine | Engine version | Detection |
Kingsoft |
2013.4.9.267 |
Win32.Troj.Dsearch.f.(kcloud) |
PC Tools |
9.0.0.2 |
SecurityRisk.Yontoo!rem |
Symantec |
20131.1.0.101 |
Yontoo |
VIPRE Antivirus |
19516 |
Yontoo (v) |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00117051% | |
Kernel CPU: | 0.00058526% | |
User CPU: | 0.00058526% | |
Kernel CPU time: | 15,625 ms/min | |
Memory |
Private memory: | 22.65 MB | |
Private (maximum): | 23.81 MB | |
Private (minimum): | 22.59 MB | |
Non-paged memory: | 22.65 MB | |
Virtual memory: | 186.47 MB | |
Virtual memory (peak): | 197.95 MB | |
Working set: | 23.55 MB | |
Working set (peak): | 23.84 MB | |
Resource allocations |
Threads: | 13 | |
Handles: | 529 | |
GUI GDI count: | 4 | |
GUI GDI peak: | 4 | |
GUI USER count: | 3 | |
GUI USER peak: | 3 | |
Process properties
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate |
37.50% |
|
Windows 8 Pro |
20.83% |
|
Microsoft Windows XP |
16.67% |
|
Windows 8 |
8.33% |
|
Windows 7 Home Premium |
8.33% |
|
Windows 7 Professional |
8.33% |
|
Distribution by country
United Kingdom installs about 16.67% of Yontoo Desktop.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Acer |
26.09% |
|
Hewlett-Packard |
17.39% |
|
Dell |
17.39% |
|
Lenovo |
17.39% |
|
Samsung |
8.70% |
|
GIGABYTE |
8.70% |
|
American Megatrends |
4.35% |
|