Home Malware Programs Adware DonutLeads

DonutLeads

Posted: October 9, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 595
First Seen: October 7, 2014
Last Seen: August 18, 2023
OS(es) Affected: Windows


DonutLeads (Donut Leads) is an adware application that may be prone to loading up random advertisements attempting to offer various products and services. Use of the DonutLeads may cause web browser applications to load other sites, basically redirecting to pages that have unwanted or questionable content. Through the DonutLeads ads displaying as banners or pop-ups, it could then cause reduced performance on certain web browsers. This will ultimately make it difficult to surf the internet. Eliminating the DonutLeads ads may be performed by use of an updated antimalware application.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\System32\Tasks\DonutQuotesHKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Tracing\DonutLeadsService_RASAPI32SOFTWARE\Microsoft\Tracing\DonutLeadsService_RASMANCSSOFTWARE\Microsoft\Tracing\donutleadssetup_tu_p_1_RASAPI32SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\DonutQuotesSOFTWARE\Wow6432Node\Microsoft\Tracing\DonutLeadsService_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\DonutLeadsService_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\donutleadssetup_tu_p_1_RASAPI32SYSTEM\ControlSet001\services\donutleadsServiceCoreSYSTEM\ControlSet001\services\eventlog\donutleadsServiceLogSYSTEM\ControlSet002\services\donutleadsServiceCoreSYSTEM\ControlSet002\services\eventlog\Application\donutleadsServiceCoreSYSTEM\ControlSet002\services\eventlog\donutleadsServiceLogSYSTEM\CurrentControlSet\services\donutleadsServiceCoreSYSTEM\CurrentControlSet\services\eventlog\Application\donutleadsServiceCoreSYSTEM\CurrentControlSet\services\eventlog\donutleadsServiceLogHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}donutleads

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\donutleads%PROGRAMFILES%\donutleads%PROGRAMFILES(x86)%\donutleads
Loading...