Home Malware Programs Adware LinkiDoo

LinkiDoo

Posted: December 9, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 878
First Seen: December 9, 2013
Last Seen: July 11, 2023
OS(es) Affected: Windows

LinkiDoo Screenshot 1LinkiDoo is adware that may come to the computer system packaged together with free software the PC user has obtained from the Web. LinkiDoo states to be able to enhance the computer user's web browsing experience by offering tools like Compare, Deals, Inline, Related, Review and Search. LinkiDoo may be dropped and installed on the computer in numerous copies. LinkiDoo may reoccur on the PC after it has been removed. To rid the PC of LinkiDoo, PC users should completely eliminate all of its components. LinkiDoo may show annoying pop-up adverts, banners, coupons and deals. LinkiDoo may hack any web browser installed on the computer and alter the default browser settings. LinkiDoo may also modify the default start page and search provider or a new tab window with a certain questionable website. LinkiDoo may install itself as an add-on, plug-in, or extension on the web browser. LinkiDoo may keep track of the web user's Internet surfing habits. LinkiDoo may gather confidential information of the PC user and forward and use it in targeted advertising campaigns.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{1F87D8B1-BC1F-435E-9290-EC13863DCAE9}{5c11f47a-dbf7-4d5f-94a0-f747ce85e935}HKEY..\..\..\..{RegistryKeys}Software\LinkiDooSoftware\Microsoft\Internet Explorer\Approved Extensions\{5C11F47A-DBF7-4D5F-94A0-F747CE85E935}SOFTWARE\Microsoft\Tracing\updateLinkiDoo_RASAPI32SOFTWARE\Microsoft\Tracing\updateLinkiDoo_RASMANCSSOFTWARE\Wow6432Node\Google\Chrome\Extensions\nedmkhahhppfofnniinaggmabnngddjkSOFTWARE\Wow6432Node\LinkiDooSOFTWARE\Wow6432Node\Microsoft\Tracing\updateLinkiDoo_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateLinkiDoo_RASMANCSSYSTEM\ControlSet001\services\eventlog\Application\Update LinkiDooSYSTEM\ControlSet001\services\Update LinkiDooSYSTEM\CurrentControlSet\services\eventlog\Application\Update LinkiDooSYSTEM\CurrentControlSet\services\Update LinkiDooHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}LinkiDoo

Additional Information

The following directories were created:
%ProgramFiles%\LinkiDoo%ProgramFiles(x86)%\LinkiDoo
The following URL's were detected:
LinkiDoo
Loading...