Home Malware Programs Browser Hijackers Yeadesktop.com

Yeadesktop.com

Posted: April 30, 2017

Threat Metric

Ranking: 3,470
Threat Level: 5/10
Infected PCs: 58,464
First Seen: April 30, 2017
Last Seen: October 17, 2023
OS(es) Affected: Windows


Yeadesktop.com is a poorly stylized page that hosts several interesting things that accompany a simple search field. Before providing details about the content hosted there, it is important to mention that users may stumble upon Yeadesktop.com while using their Web browser even if they had not heard of this page ever before. This may happen because Yeadesktop.com uses browser hijacking software to modify a Web browser's settings so that its new tab page and homepage will be set to Yeadesktop.com. Naturally, this does not happen without installing the hijacking software, and that's why users who experience this issue should think carefully if they've installed software that may have brought the hijacker to their computers recently.

In its current state, Yeadesktop.com includes a collection of quick links to popular websites, as well as an automatic scrolling Twitter feed, which claims to provide users with funny jokes and quotes. Last but not least, below the search bar uses will find a collection of free online games that can be played from their Web browser directly. However, the most important part of every search page appears to be dysfunctional in the case of Yeadesktop.com – entering any search term in the search bar and hitting the 'Search' button does absolutely nothing.

If you see Yeadesktop.com when you launch your Web browser, then it is strongly recommended to take the required actions to uninstall the software that brought this program to your computer. This task may be difficult to carry out manually so that it is a good idea to put this chore in the hands of a skilled anti-malware scanner that will automate the removal process.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 5.83 MB (5836525 bytes)
MD5: a7e0cc34ef30b4a18fa4ab8b9061a004
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 6, 2020

Registry Modifications

The following newly produced Registry Values are:

File name without pathhttp_www.yeadesktop.com_0.localstoragehttp_www.yeadesktop.com_0.localstorage-journalhttp_www.yeadesktopbr.com_0.localstoragehttp_www.yeadesktopbr.com_0.localstorage-journalwww.bengpala[1].xmlYeaDesktop.lnkHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\DOMStorage\bengpala.cnSoftware\Microsoft\Internet Explorer\DOMStorage\www.bengpala.cnSoftware\Microsoft\Internet Explorer\DOMStorage\www.yeadesktop.comSoftware\Microsoft\Internet Explorer\DOMStorage\www.yeadesktopbr.comSoftware\Microsoft\Internet Explorer\DOMStorage\yeadesktop.comSoftware\Microsoft\Internet Explorer\DOMStorage\yeadesktopbr.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.yeadesktop.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.yeadesktopbr.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\yeadesktop.comSOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\yeadesktopbr.comSOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\YeaDesktop.exeSOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\YeaDesktop.exeSOFTWARE\Microsoft\Tracing\Yeadesktop_RASAPI32SOFTWARE\Microsoft\Tracing\Yeadesktop_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Run\YeaDesktopSoftware\PritcSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\YeaDesktop.exeSOFTWARE\WOW6432Node\Microsoft\Tracing\yeadesktop2_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Yeadesktop_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Yeadesktop_RASMANCSSoftware\YeaDesktopHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}YeaDesktop

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\YeaDesktop%APPDATA%\Microsoft\Windows\Start Menu\Programs\YeaDesktop%APPDATA%\servertest%PROGRAMFILES%\YeaDesktop%PROGRAMFILES(x86)%\YeaDesktop
The following URL's were detected:
yeadesktop.comyeadesktopbr.com
Loading...