We received the file YONTOOFFCLIENT.XPI and detected that YONTOOFFCLIENT.XPI is not good.
YONTOOFFCLIENT.XPI is Adware. You should remove the file YONTOOFFCLIENT.XPI.
Kill the process YONTOOFFCLIENT.XPI and remove YONTOOFFCLIENT.XPI from Windows.
Malware Analysis of YONTOOFFCLIENT.XPI
Full path on a computer: %TEMP%\YONTOOFFCLIENT.XPI
Detected by UnHackMe:
YONTOOFFCLIENT.XPI
Default location: %TEMP%\YONTOOFFCLIENT.XPI
Removal Results: Success
Number of reboot: 1
YONTOOFFCLIENT.XPI is known as:
Adware Yontoo
YONTOOFFCLIENT.XPI hash:
-
MD5: 29CBBED71260698B72AE5DD8352B4790
How to quickly detect YONTOOFFCLIENT.XPI presence?
Files:
- %COMMONAPPDATA%\MICROSOFT\NETWORK\DOWNLOADER\QMGR0.DAT
- %COMMONAPPDATA%\MICROSOFT\NETWORK\DOWNLOADER\QMGR1.DAT
- %COMMONAPPDATA%\TARMA INSTALLER\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\SETUP.DAT
- %COMMONAPPDATA%\TARMA INSTALLER\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\SETUP.EXE
- %TEMP%\YONTOOFFCLIENT.XPI