Home Malware Programs Browser Hijackers Yokeline.com

Yokeline.com

Posted: February 28, 2012

Yokeline.com Screenshot 1Yokeline.com is a fake search engine that belongs to a larger group of identical sites, all of which supply results that lead you to advertisements and trash content. While Yokeline.com wouldn't be especially notable for these traits by themselves, SpywareRemove.com malware experts are concerned with Yokeline.com and its clone sites due to their promotion by browser-hijacking PC threats. These PC threats can redirect your browser to Yokeline.com (often via other search engine sites) and will attack all types of web browsers indiscriminately. If your browser starts heading to Yokeline.com without your permission, it's recommended for you to give a trustworthy brand of anti-malware software a chance to analyze your PC and disinfect all Yokeline.com-related PC threats.

Relatives of Yokeline.com That Work Right Alongside It

Yokeline.com looks like a functional if basic search engine, but the actual search engine features behind Yokeline.com's appearance can be considered effectively nonexistent. Instead of searching the web for real results, Yokeline.com will share out links that return profit to Yokeline.com through affiliate deals and advertising-based agreements.
In fact, there are quite a few sites that could pass for twins to Yokeline.com, all of which should be accorded an equal lack of trust compared to Yokeline.com. Other sites in this click fraud-profiting ring of faux search engines can, in most cases, be identified by their green globe emblem superimposed on a gray background. Their numbers include such domains as Resultoffer.com, Hitpush.com, QueryExplorer.com, Placelow.com, QueryScan.com, Crownhub.com, Papergap.com, QuestDNS.com and ScanBasic.com.

Getting Your Web Browser Yoked to Yokeline.com

Because Yokeline.com doesn't try to advertise itself like a normal website would, your first means of contact with Yokeline.com is almost certainly going to be a browser hijacker that's installed onto your PC without permission. Browser hijackers that are associated with Yokeline.com's family of dummy search engines will redirect your browser from legitimate search sites to Yokeline.com, but they may also be capable of causing other problems (such as creating pop-ups, disabling your browser's security or locking your homepage to Yokeline.com). Yokeline.com-promoting browser hijackers may also attack multiple types of web browsers and shouldn't be considered to be add-ons for specific brands of browser programs.

Once you see Yokeline.com redirects or related problems you should run a scan of your PC with a good anti-malware program. Browser hijackers are often accompanied by other forms of malicious software, such as Trojans or rootkits, all of which should be deleted with competent security software. Any delay in attending to your Yokeline.com redirecting problem can result in a less-secure web-surfing experience than the norm, encompassing the possibility of losing personal information that's associated with account-based websites.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%AppData%[trojan name]toolbarstats.dat File name: %AppData%[trojan name]toolbarstats.dat
File type: Data file
Mime Type: unknown/dat
%AppData%[trojan name]toolbarstat.log File name: %AppData%[trojan name]toolbarstat.log
Mime Type: unknown/log
%AppData%[trojan name]toolbarpreferences.dat File name: %AppData%[trojan name]toolbarpreferences.dat
File type: Data file
Mime Type: unknown/dat
%AppData%[trojan name]toolbarcouponsmerchants2.xml File name: %AppData%[trojan name]toolbarcouponsmerchants2.xml
Mime Type: unknown/xml
%AppData%[trojan name]toolbarcouponsmerchants.xml File name: %AppData%[trojan name]toolbarcouponsmerchants.xml
Mime Type: unknown/xml
%AppData%[trojan name]toolbarcouponscategories.xml File name: %AppData%[trojan name]toolbarcouponscategories.xml
Mime Type: unknown/xml
%AppData%[trojan name]toolbarlog.txt File name: %AppData%[trojan name]toolbarlog.txt
Mime Type: unknown/txt
%AppData%[trojan name]toolbarguid.dat File name: %AppData%[trojan name]toolbarguid.dat
File type: Data file
Mime Type: unknown/dat
%AppData%[trojan name]toolbardtx.ini File name: %AppData%[trojan name]toolbardtx.ini
Mime Type: unknown/ini
%AppData%[trojan name]toolbarversion.xml File name: %AppData%[trojan name]toolbarversion.xml
Mime Type: unknown/xml
%AppData%[trojan name]toolbaruninstallStatIE.dat File name: %AppData%[trojan name]toolbaruninstallStatIE.dat
File type: Data file
Mime Type: unknown/dat
%AppData%[trojan name]toolbaruninstallIE.dat File name: %AppData%[trojan name]toolbaruninstallIE.dat
File type: Data file
Mime Type: unknown/dat
%Temp%[trojan name]toolbar-manifest.xml File name: %Temp%[trojan name]toolbar-manifest.xml
Mime Type: unknown/xml

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\[trojan name]IEHelper.DNSGuardHKEY_LOCAL_MACHINE\SOFTWARE\Classes\[trojan name]IEHelper.DNSGuard.1HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ "[trojan name] Toolbar"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}ProgID "[trojan name]IEHelper.UrlHelper.1"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 "C:PROGRA~1WINDOW~4ToolBar[trojan name]dtx.dll"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID "[trojan name]IEHelper.UrlHelper"HKEY_LOCAL_MACHINE\SOFTWARE\Classes\[trojan name]IEHelper.DNSGuardCurVerHKEY_LOCAL_MACHINE\SOFTWARE\Classes\[trojan name]IEHelper.DNSGuardCLSID
Loading...