Content

Adware-Adtomi

Type
Program
SubType
Adware
Discovery Date
08/07/2003
Minimum DAT
4285 (08/13/2003)
Updated DAT
5355 (08/06/2008)
Minimum Engine
5.1.00
Description Added
08/07/2003
Description Modified
08/26/2003 2:32 AM (PT)

Tab Navigation

Characteristics

This is not a virus nor a trojan. It is a direct-marketing adware application. This application generates extra pop-up ads while using Internet Explorer.

This kind of application generally comes bundled with another program, which usually discloses the fact that it is ad-supported. It is currently bundled with a program called YahooStocks, but may be bundled with other programs as well. Users agree to have the Adware installed in the license agreement, although they may not realise at first that this file was packaged with the product they installed.

The following system changes were observed when running this application:

Added files

  • c:\WINDOWS\YSTCKAO32.EXE

    Added registry keys

  • HKEY_CURRENT_USER\Software\adtomi
    "homepage" = http://www.zestyfind.com

  • HKEY_CURRENT_USER\Software\adtomi
    "redirecturl" = http://www.zestyfind.com/DNS.php

  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    "YahooStock" = C:\WINDOWS\YSTCKAO32.EXE

    The Start page for Internet Explorer is also changed to point to the Zestyfind website.

    The detection of this type of file is not automatically activated. Users who would like to check for the presence of this kind of files on their system should run the command line scanner with the /PROGRAM switch. Please note that VirusScan 7 has also an option, which enables users to detect this kind of program automatically (see below).

  • Aliases

    Aliases

      N/A