Home Malware Programs Adware Search Donkey

Search Donkey

Posted: June 19, 2013

Threat Metric

Ranking: 12,332
Threat Level: 2/10
Infected PCs: 2,590
First Seen: June 19, 2013
Last Seen: October 3, 2023
OS(es) Affected: Windows

Search Donkey is a browser extension/potentially unwanted program that was developed by WebAppTech Coding, LLC. Search Donkey states to provide web users with more browsing options for Internet Explorer, Mozilla Firefox and Google Chrome. Search Donkey enters the vulnerable PC together with other freeware programs without the computer user knowing about it. Once inside the affected computer system, Search Donkey makes changes to the hacked web browser when the PC user is making an online search or visiting certain websites. Search Donkey will display a drop-down menu, which is named 'Best Search'. Although Search Donkey is not a malicious application, it is still included in the list of programs that security experts recommend to remove from the PC. Search Donkey can result in unwanted redirects to doubtful websites where computer users can get their PCs affected by various malware threats. Also Search Donkey can keep track of the victim's browsing habits and, thus, violate the attacked PC user's privacy. Search Donkey can easily get access to the target computer user's login information and also sell the data about the victim's most visited websites to the third parties. Search Donkey will display pop-up ads on the infected computer system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\SearchDonkey\up\2.6.80\SearchDonkeyService.exe File name: SearchDonkeyService.exe
Size: 48.54 KB (48545 bytes)
MD5: 2e256b6a5a21993547ab56f9f65ef245
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\SearchDonkey\up\2.6.80
Group: Malware file
Last Updated: March 26, 2016

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{44ED99E2-16A6-4B89-80D6-5B21CF42E78B}SOFTWARE\Microsoft\Tracing\SearchDonkey_RASAPI32SOFTWARE\Microsoft\Tracing\SearchDonkey_RASMANCSSoftware\Mozilla\Firefox\Extensions\support@searchdonkeyapp.comSOFTWARE\Wow6432Node\Microsoft\Tracing\SearchDonkey_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchDonkey_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\SearchDonkeyService_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\SearchDonkeyService_RASMANCSHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SearchDonkey

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\SearchDonkey%PROGRAMFILES%\SearchDonkey%PROGRAMFILES(x86)%\SearchDonkey
The following URL's were detected:
SearchDonkey
Loading...