|
What is Wowlook and removal instructions
Wowlook is an Internet worm that spreads by e-mail through messages with infected attachments. Once the user opens such an attachment, the parasite secretly installs itself to the system and runs a spreading routine. It sends bogus e-mails to all the addresses it finds the Windows Address Book and gathers from Outlook Express. Then Wowlook runs a payload. It searches for the World of Warcraft installation. If it finds one, it attempts to steal passwords and login details to this online game. Stolen data is transferred to a predetermined web site. Wowlook also modifies local web and program source files to insert links to malicious sites. The worm runs on every Windows startup.
Wowlook manual removal: Kill processes: setupv9.exe
Delete registry values: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\1
Delete files: setupv9.exe, srvpl0.dll, setupv9.zip
Misc: The setupv9.zip file arrives attached to Wowlook e-mail messages.
Other Wowlook files reside in default system directory, which is C:\WINDOWS\System32 or C:\WINNT\System32.
|
|
|
|
|