Yokelead.com

By GoldSparrow in Browser Hijackers

Yokelead.com Image

Criminals behind Yokelead.com are responsible for hundreds of fake search engines sporting identical interfaces and layouts. It is not abnormal for criminals to create numerous clones of their malware infections and attack websites in order to stay one step ahead of PC security analysts. Fake search engines in the Yokelead.com family tend to use a white or light-gray background, and a logo consisting of either a magnifying glass or a globe, also in gray with light blue or green highlights. Paradoxically, this minimalist layout tends to be quite more effective at attracting victims than other websites that go overboard in creating fake link directories and non-existing features for their fake search engines.

Yokelead.com and its clones are not particularly dangerous in themselves. If you simply visit Yokelead.com, it is not likely to infect your computer with malware (although we definitely do not recommend it, especially since it would not be difficult for criminals to modify Yokelead.com in order to make Yokelead.com distribute malware more directly). However, because of its involvement in a dangerous online scam which involves various different kinds of malware, PC security analysts consider websites like Yokelead.com as severe threats to your computer system's safety. ESG malware researchers strongly recommend running a full scan of your computer system after any contact with the Yokelead.com website, or with any of its clones.

Yokelead.com is not a real search engine, despite its appearance. Trying out a search on this website will simply result in a stream of spam and links to websites actively involved in distributing malware and selling fraudulent products. So, there is no need to use Yokelead.com for their search needs? Well, the fact is that most people that end up using Yokelead.com have no choice in the matter. This is because Yokelead.com is closely related to a type of infection called browser hijacker. Browser hijackers are malware threats that basically take over the victim's computer system in order to affect how it connects to the Internet. Computer systems infected with Yokelead.com-related browser hijackers end up forcing the computer user to visit Yokelead.com repeatedly when using the web browser. This allows criminals to profit from advertising and other pay per click schemes, since each time victims are forced to view Yokelead.com's fake search results, they are generating advertisement views, clicks, and impressions for the criminals responsible for Yokelead.com.

File System Details

Yokelead.com may create the following file(s):
# File Name Detections
1. %AppData%[trojan name]toolbaruninstallIE.dat
2. %AppData%[trojan name]toolbarversion.xml
3. %AppData%[trojan name]toolbarcouponsmerchants2.xml
4. %AppData%[trojan name]toolbarstats.dat
5. %Temp%[trojan name]toolbar-manifest.xml
6. %AppData%[trojan name]toolbarcouponsmerchants.xml
7. %AppData%[trojan name]toolbarguid.dat
8. %AppData%[trojan name]toolbaruninstallStatIE.dat
9. %AppData%[trojan name]toolbarcouponscategories.xml

Registry Details

Yokelead.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 "C:PROGRA~1WINDOW~4ToolBar[trojan name]dtx.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuard
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuardCLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID "[trojan name]IEHelper.UrlHelper"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuardCurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "[trojan name] Toolbar"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}ProgID "[trojan name]IEHelper.UrlHelper.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuard.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"

Trending

Most Viewed

Loading...