Remove Lokkest. Description and removal instructions

 
Title: Lokkest

Type: Worms
Severity scale:Lokkest severity is 64  (64 / 100)
 
Lokkest is a complex Internet worm that spreads by e-mail through messages with infected attachments that can be screensavers, archives, images or text documents. Once the user opens such an attachment, the parasite secretly installs itself to the system and runs a spreading routine.

The worm uses own mail engine to send bogus e-mails to addresses it gathers from local program, text and web files. Lokkest can also propagate through instant messages using Yahoo! Messenger, ICQ, AIM and MSN Messenger programs. Furthermore, it is able to spread to computers running MS SQL Server and network shares protected by weak passwords. The parasite can infect computers running unpatched Symantec, Microsoft and RealVNC software.

Lokkest carries a dangerous payload. It terminates running antiviruses, firewalls and anti-spyware programs. It attempts to open a back door providing the attacker with unauthorized remote access to the compromised computer. The intruder can download and execute files, log user keystrokes, steal MSN Messenger passwords, intercept network traffic and run a hidden proxy server. The worm is able to change some system settings and modify essential system files.

Lokkest runs as a service on every Windows startup.


Related files: mutex.exe

Lokkest properties:
• Allows remote user connection
• Logs keystrokes
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Lokkest removal:

remover for Lokkest

Lokkest manual removal:

Kill processes:
mutex.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows Mutex Object
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_MUTEX_OBJECT
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Windows Mutex Object
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDOWS_MUTEX_OBJECT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\EnableDCOM=n
Delete files:
mutex.exe
Misc:
The mutex.exe file can be found in C:\WINDOWS\System32\dllcache or C:\WINNT\System32\dllcache folder.

Lokkest can modify the system file tcpip.sys that resides in the following directories: C:\WINDOWS\System32\drivers, C:\WINDOWS\System32\dllcache, C:\WINDOWS\ServicePackFiles\i386.

Other programs to remove Lokkest:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 06/01/07
Information updated: 06/01/07

Additional resources related to Lokkest:

Attention: If you know or you have a website or page about Lokkest removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Lokkest parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: