Home Malware Programs Adware Adware.Lookinglink

Adware.Lookinglink

Posted: January 30, 2014

Threat Metric

Ranking: 8,743
Threat Level: 2/10
Infected PCs: 1,248
First Seen: January 30, 2014
Last Seen: October 10, 2023
OS(es) Affected: Windows


Adware.Lookinglink is adware/a potentially unwanted browser add-on that claims to make a PC user's Web browsing activity more effective by displaying discount coupons and allowing comparison shopping. Adware.Lookinglink may install itself on the Web browsers such as Internet Explorer, Google Chrome, and Mozilla Firefox without the computer user's authorization using misleading techniques. Adware.Lookinglink may usually spread and penetrate into the PC through packed free software. When installed, Adware.Lookinglink may generate and display unwanted pop-up advertisements and messages carrying various sale deals and offers. Adware.Lookinglink may keep track of the computer user's Internet surfing routine by recording an IP address, unique identifier number, browser information, operating system, search queries entered, web pages visited, websites viewed, and other information.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



lookinglinkUninstall.exe File name: lookinglinkUninstall.exe
Size: 239.85 KB (239858 bytes)
MD5: 26ba7977ef38be7f3748d7b619e4bb21
Detection count: 25
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 30, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{17513F18-4EB9-49B5-881C-465A2688C87F}{6A4E1F74-0375-4CFF-9406-281C94F865C5}{84dfb3ca-9212-4fba-bf3a-a66c4a02a48f}{EB317E41-9AA7-487A-8060-B81657E8D68A}File name without path{7f6d153f-9819-4c98-96fb-5c6aa213f0ea}.xpiHKEY..\..\..\..{RegistryKeys}Software\lookinglinkSoftware\Microsoft\Internet Explorer\Approved Extensions\{02A8433A-1DA4-41BE-8F4A-D7E5B15AAB40}SOFTWARE\Microsoft\Tracing\updatelookinglink_RASAPI32SOFTWARE\Microsoft\Tracing\updatelookinglink_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{84dfb3ca-9212-4fba-bf3a-a66c4a02a48f}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{84DFB3CA-9212-4FBA-BF3A-A66C4A02A48F}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{84DFB3CA-9212-4FBA-BF3A-A66C4A02A48F}SOFTWARE\Wow6432Node\lookinglinkSOFTWARE\Wow6432Node\Microsoft\Tracing\updatelookinglink_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatelookinglink_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{84dfb3ca-9212-4fba-bf3a-a66c4a02a48f}SYSTEM\ControlSet001\services\eventlog\Application\Update lookinglinkSYSTEM\ControlSet001\services\Update lookinglinkSYSTEM\ControlSet002\services\eventlog\Application\Update lookinglinkSYSTEM\ControlSet002\services\Update lookinglinkSYSTEM\CurrentControlSet\services\eventlog\Application\Update lookinglinkSYSTEM\CurrentControlSet\services\Update lookinglinkHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}lookinglink

Additional Information

The following directories were created:
%PROGRAMFILES%\lookinglink%PROGRAMFILES(X86)%\lookinglink
The following URL's were detected:
lookinglink
Loading...