Adware

Adware.Yontoo (file analysis)

Malware Removal

The Adware.Yontoo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Yontoo virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Creates a copy of itself

Related domains:

ocsp.verisign.com
sf.symcd.com
install.specialboxsite.com

How to determine Adware.Yontoo?


File Info:

crc32: 85ECD906
md5: 937a836155e9a33e9e4902d2953ff167
name: SpecialBoxUninstaller.exe
sha1: 68efd3f9d9abb583bc4c641e68fff296b4acdc08
sha256: 8d0f57057f6fce840502b4e1628a9e16e021c4d4af5eadf4a9f54a895b4d48e3
sha512: b8b319744cbfd3073fe84194d1d60b55d468247ccd60ebc785c2b6a70e05d390e6685353da57c1850cd9c41ca5fb2cc7b6282689ffa9ab8eed6648e4f4036122
ssdeep: 6144:hcnpVZFphwVEufwj1hW6AAgKjIOvuJaL0NVXBVcmiaNbXPpUQ2cQr0tZ5/ai0kPG:hcnpVZFphwVEuIj1hVIeqRa/Qr5pbpc
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: Special Box Uninstaller.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: Special Box Uninstaller.exe

Adware.Yontoo also known as:

MicroWorld-eScanGen:Variant.Adware.MSILPerseus.1523
FireEyeGeneric.mg.937a836155e9a33e
CAT-QuickHealPUA.AdwareFC.S7914100
ALYacGen:Variant.Adware.MSILPerseus.1523
MalwarebytesAdware.Yontoo
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 004c4fe71 )
BitDefenderGen:Variant.Adware.MSILPerseus.1523
K7GWAdware ( 004c4fe71 )
Cybereasonmalicious.155e9a
TrendMicroTROJ_GEN.R002C0GGU19
F-ProtW32/S-4623373a!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.BrowseFox.O
APEXMalicious
GDataGen:Variant.Adware.MSILPerseus.1523
Kasperskynot-a-virus:HEUR:AdWare.MSIL.BrowseFox.gen
AlibabaAdWare:MSIL/BrowseFox.f516eb5d
NANO-AntivirusRiskware.Win32.Yontoo.eutrba
AegisLabAdware.MSIL.Generic.2!c
AvastMSIL:BrowseFox-IV [Adw]
Ad-AwareGen:Variant.Adware.MSILPerseus.1523
EmsisoftApplication.BrowserExt (A)
ComodoApplication.MSIL.BrowseFox.AO@60es5y
F-SecureAdware.ADWARE/BrowseFox.Gen7
DrWebTrojan.Yontoo.1735
ZillyaAdware.BrowseFoxCRTD.Win32.5279
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
SophosGeneric PUA GI (PUA)
IkarusPUA.Multiplug
CyrenW32/S-4623373a!Eldorado
WebrootPua.Browsefox
AviraADWARE/BrowseFox.Gen7
MAXmalware (ai score=60)
Antiy-AVLTrojan/Win32.TSGeneric
Endgamemalicious (high confidence)
ArcabitTrojan.Adware.MSILPerseus.D5F3
SUPERAntiSpywarePUP.SpecialBox/Variant
AhnLab-V3PUP/Win32.BrowseFox.R152414
ZoneAlarmnot-a-virus:HEUR:AdWare.MSIL.BrowseFox.gen
MicrosoftBrowserModifier:Win32/Foxiebro
McAfeeArtemis!937A836155E9
VBA32TScope.Trojan.MSIL
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0GGU19
TencentMalware.Win32.Gencirc.10b618d4
YandexPUA.Agent!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetAdware/Generic
AVGMSIL:BrowseFox-IV [Adw]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Generic/Virus.Adware.d0c

How to remove Adware.Yontoo?

Adware.Yontoo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment