Home Malware Programs Potentially Unwanted Programs (PUPs) Whilokii

Whilokii

Posted: October 7, 2013

Threat Metric

Ranking: 10,936
Threat Level: 2/10
Infected PCs: 23,309
First Seen: October 7, 2013
Last Seen: September 14, 2023
OS(es) Affected: Windows

Whilokii Screenshot 1Whilokii is an adware program that modifies your browser to display additional advertisements, and also may make other unwanted settings adjustments (such as changing your homepage or default search engine). Although these functions are merely inconveniences more than anything else, their persistence and tendency to change your browser's behavior do make Whilokii a low-level security hazard. Uninstalling Whilokii always should be done whenever possible, but, with its history of trying to avoid being removed, applying anti-malware software to the situation may be your best hope of actually getting Whilokii off of your computer.

Skipping Your Way from Skype to Whilokii

Whilokii is adware that, similar to other adware 'products' without any interest in benefiting you, prefers to install itself through bundles with unrelated applications. Malware researchers recently verified Whilokii's distribution with compromised Skype installers, although it should be stressed that this warning doesn't apply to legitimate Skype downloads from official sources. Victims of these attacks usually will not notice Whilokii's installation until after their browser begins displaying its dominant characteristic: advertisements.

Whilokii may inject banner advertisements into unrelated Web pages, insert additional advertising links above your search results and, as adding insult to injury, may also hijack your homepage. Since Whilokii still is being developed and distributed on an active basis, other modifications to your browser that aren't listed here also may occur. Although sites and advertisement content promoted by Whilokii are not deliberately unsafe, Whilokii still may expose you to other PC threats through careless or a lack of due regard for the safety of your PC. Some PC security companies label Whilokii as a PUP or a threat, based on its distribution methods and related factors.

Whiling Away the Time without Whilokii

As if to add a final bit of emphasis to just how little Whilokii cares for its actual users, Whilokii tries to prevent you from uninstalling Whilokii whenever you make an attempt at such a thing through standardized methods like the Control Panel. Even some specialized uninstallation utilities have been blocked by Whilokii, and malware experts must recommend the use of qualified anti-malware products for removing Whilokii without any unforeseen obstacles. Using general and thorough anti-malware scans while deleting Whilokii is a recommended precaution for identifying any other PC threats that also may have been installed through the software bundle that carried Whilokii.

With a history of using disguised installers related to official products, Whilokii can most easily be avoided by staying clear of unofficial software-downloading sources. Always download official products directly from the relevant company whenever possible. If this isn't possible, scanning a suspicious installation file with anti-malware tools can detect a possible Whilokii payload hiding inside – without needing to infect your Web browser in the process.

Aliases

Adware/Win32.Downloader [AhnLab-V3]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\Whilokii\updateWhilokii.exe File name: updateWhilokii.exe
Size: 65.3 KB (65304 bytes)
MD5: b1ec2caa074a857bf98ca990e576bc2d
Detection count: 19,154
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Whilokii\updateWhilokii.exe
Group: Malware file
Last Updated: November 8, 2021
C:\Users\<username>\AppData\Local\Temp\is357113909\454728467_stp\whilokii_is.exe File name: whilokii_is.exe
Size: 202.83 KB (202832 bytes)
MD5: 655d2f50763b7f9370ebbf9ddad80555
Detection count: 101
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\is357113909\454728467_stp\whilokii_is.exe
Group: Malware file
Last Updated: May 18, 2022
C:\Program Files (x86)\Whilokii\WhilokiiUninstall.exe File name: WhilokiiUninstall.exe
Size: 212.27 KB (212279 bytes)
MD5: cdd3ad36723e7a2c19fc50d518ce7a91
Detection count: 87
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Whilokii\WhilokiiUninstall.exe
Group: Malware file
Last Updated: April 8, 2021
iaimhpklononapfjngelgdokckfjekfc.crx File name: iaimhpklononapfjngelgdokckfjekfc.crx
Size: 3.39 KB (3394 bytes)
MD5: b0425b5a9a5da1d822c14901dda4960d
Detection count: 30
Mime Type: unknown/crx
Group: Malware file
Last Updated: January 29, 2021
file.exe File name: file.exe
Size: 284.75 KB (284752 bytes)
MD5: d5e311616d27443a22c6d76f4488a935
Detection count: 4
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 8, 2020

Registry Modifications

The following newly produced Registry Values are:

CLSID{204df522-9a96-4a72-abb0-60f7a216d6d2}{8B0295E2-967E-439E-9560-807D9F625B57}{AB4DA692-F26B-403C-AF8F-FD87D121F8F1}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Tracing\updateWhilokii_RASAPI32SOFTWARE\Microsoft\Tracing\updateWhilokii_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{204df522-9a96-4a72-abb0-60f7a216d6d2}Software\WhilokiiSOFTWARE\Wow6432Node\Microsoft\Tracing\updateWhilokii_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateWhilokii_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{204df522-9a96-4a72-abb0-60f7a216d6d2}SOFTWARE\Wow6432Node\WhilokiiSYSTEM\ControlSet001\services\eventlog\Application\Update WhilokiiSYSTEM\ControlSet001\services\Update WhilokiiSYSTEM\CurrentControlSet\services\eventlog\Application\Update WhilokiiSYSTEM\CurrentControlSet\services\Update WhilokiiHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Whilokii

Additional Information

The following directories were created:
%ProgramFiles%\Whilokii%ProgramFiles(x86)%\Whilokii
The following URL's were detected:
Whilokii
Loading...