Yeadesktop.com

By GoldSparrow in Browser Hijackers

Threat Scorecard

Ranking: 3,406
Threat Level: 50 % (Medium)
Infected Computers: 24,932
First Seen: April 30, 2017
Last Seen: September 21, 2023
OS(es) Affected: Windows

The Yeadesktop.com domain is presented to Web surfers as a search service that includes links to third-party service like LinkedIn, Netflix, Yahoo, YouTube and Facebook. Yeadesktop.com offers visitors access to curated collection of Web-based mini-games as well. The site may appeal to users of all ages, but you should take into consideration that Yeadesktop.com is supported by intrusive advertisements. Additionally, Yeadesktop.may be associated with a program with the same name ('Yeadesktop') that is mentioned in cases of browser hijacking. Computer users that are affected by the Yeadesktop browser hijacker have reported that their Internet browser loads Yeadesktop.com as the default start page and new tab. We have detected that a program with the name 'Yeadesktop' may be delivered to PC users via free software bundles and make modifications to their Internet settings. There is no official page for the 'Yeadesktop' app but we have found that there are direct links to subpages on Yeadesktop.com that include:

  • down.yeadesktop[.]com/YeaDesktop/yeadesktop_51504.exe
  • down.yeadesktop[.]com/offer/msiql.exe
  • down.yeadesktop[.]com/offer/hp.exe
  • down.yeadesktop[.]com/offer/service.exe
  • down.yeadesktop[.]com/YeaDesktop/yeadesktop_51495.exe
  • down.yeadesktop[.]com/YeaDesktop/yeadesktop_51471.exe
  • down.yeadesktop[.]com/offer/kpzip.exe
  • down.yeadesktop[.]com/yeadesk/yeadesktop.ex

The programs available via Yeadesktop.com appear to be designed as browser hijackers that aim to drive Web traffic to Yeadesktop.com and connected sites. Yeadesktop.com may be flagged as an unreliable search service that may redirect users to phishing pages and welcome visitors to install apps like DailyPrize and ZoomApp. It is recommended that you avoid the download of software associated with Yeadesktop.com. The browser hijacker linked to Yeadesktop.com may be used to display corrupted ads on your screen, and you may want to use a trustworthy anti-malware scanner to clean your machine. AV vendors are known to detect the files connected to 'Yeadesktop' as:

  • ADWARE/Agent.eukcm
  • Gen:Variant.Zusy.232929 (B)
  • Generic PUA LA (PUA)
  • PUP.InstallCore/Variant
  • Trojan.Zusy.D38DE1
  • Win32.Adware.Sokuxuan.Dzuk
  • Win32:Adware-gen [Adw]

SpyHunter Detects & Remove Yeadesktop.com

File System Details

Yeadesktop.com may create the following file(s):
# File Name MD5 Detections
1. file.exe a7e0cc34ef30b4a18fa4ab8b9061a004 14

Registry Details

Yeadesktop.com may create the following registry entry or registry entries:
File name without path
http_www.yeadesktop.com_0.localstorage
http_www.yeadesktop.com_0.localstorage-journal
http_www.yeadesktopbr.com_0.localstorage
http_www.yeadesktopbr.com_0.localstorage-journal
www.bengpala[1].xml
YeaDesktop.lnk
Software\Microsoft\Internet Explorer\DOMStorage\bengpala.cn
Software\Microsoft\Internet Explorer\DOMStorage\www.bengpala.cn
Software\Microsoft\Internet Explorer\DOMStorage\www.yeadesktop.com
Software\Microsoft\Internet Explorer\DOMStorage\www.yeadesktopbr.com
Software\Microsoft\Internet Explorer\DOMStorage\yeadesktop.com
Software\Microsoft\Internet Explorer\DOMStorage\yeadesktopbr.com
SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.yeadesktop.com
SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.yeadesktopbr.com
SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\yeadesktop.com
SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\yeadesktopbr.com
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\YeaDesktop.exe
SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\YeaDesktop.exe
SOFTWARE\Microsoft\Tracing\Yeadesktop_RASAPI32
SOFTWARE\Microsoft\Tracing\Yeadesktop_RASMANCS
Software\Microsoft\Windows\CurrentVersion\Run\YeaDesktop
Software\Pritc
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\YeaDesktop.exe
SOFTWARE\WOW6432Node\Microsoft\Tracing\yeadesktop2_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\Yeadesktop_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\Yeadesktop_RASMANCS
Software\YeaDesktop

Directories

Yeadesktop.com may create the following directory or directories:

%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\YeaDesktop
%APPDATA%\Microsoft\Windows\Start Menu\Programs\YeaDesktop
%APPDATA%\servertest
%PROGRAMFILES%\YeaDesktop
%PROGRAMFILES(x86)%\YeaDesktop

URLs

Yeadesktop.com may call the following URLs:

yeadesktop.com
yeadesktopbr.com

Trending

Most Viewed

Loading...