Yontoo Trojan tries to lure Mac users with movie trailers

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
NBC News said:
1C6560557-yontoo1.streams_desktop_medium.jpg

Trojan.Yontoo.1 is a nasty bit of software. Already known to security researchers, it has begun sneaking onto computers running OS X by installing an adware plugin via the Chrome, Firefox and Safari Web browsers.

The toxic plugin brings additional ads to the user, part of a money-making scheme if you click on them — but more importantly gives outsiders access to track your Web surfing.

Russian security firm Dr. Web reported the problem, noting that "adware for Mac OS X has been increasing in number since the beginning of 2013. Trojan.Yontoo.1 is the most prominent of them: It can download and install an adware browser plugin in an infected system."

Symantec, too, has taken note of the Trojan for Windows users, where it installs a Web browser extension that displays ads that "appear to be from Facebook."

NBC News asked Apple about Trojan.Yontoo.1, but the company declined to comment.

Dr. Web says there are "several ways" for the Trojan to get onto a computer. Among them are movie trailer pages that ask users to install a browser plugin. In fact, "the prompt only imitates a common dialogue displayed when a plugin needs to be installed or additional configuration is necessary. After clicking on 'Install the plug-in,' the user is redirected to another site from which Trojan.Yontoo.1 is downloaded."

Trojan.Yontoo.1 can also be downloaded as a media player, video quality "enhancement program" or a download accelerator, the firm says.

Read more: http://www.nbcnews.com/technology/technolog/yontoo-trojan-tries-lure-mac-users-movie-trailers-1C8995971
 

Gnosis

Level 5
Apr 26, 2011
2,779
Isn't Yontoo legit though. I mean grayware maybe, but this thread explains a trojan posing as a Yontoo plugin, right?
 

Fiery

Level 1
Jan 11, 2011
2,007
Yontoo can be considered as ad-ware, I would remove it if it's on a PC

http://www.avira.com/en/support-threats-description/tid/7311/adware_yontoo.a.13.html

http://forums.spybot.info/showthread.php?t=62640
 

Gnosis

Level 5
Apr 26, 2011
2,779
That is what I thought, Fiery. I consider it more adware/grayware/spam; bordering on advertising spyware than a catastrophic threat of any kind.
I agree with you though----GET IT OUT OF THERE!!
I had it a while back. I just uninstalled it and ran HiJackThis and checked a few boxes followed by "fix".
Problem solved.

Yontoo and Delta Search are two more reasons I like to keep HiJackThis handy. It is outdated, but it still cleans up this kind of browser manipulation really well.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Yontoo just like others are not to say harmful but makes it slowdown for browsing matters and adds unnecessarily features.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top