Remove Wombat. Description and removal instructions

 
Title: Wombat

Type: Trojans
Severity scale:Wombat severity is 67  (67 / 100)
 
Wombat is a dangerous trojan that corrupts the infected system. Once executed, it secretly installs itself to the system and runs a payload. The parasite attempts to terminate and then cripple installed antiviruses and security-related programs. It also attempts to delete vital Windows files and folders, and thus destroy the entire system. Furthermore, Wombat disables essential system tools, functions and components such as Registry Editor, Task Manager, CD Burning and Windows Firewall. It can shutdown the compromised computer without asking for user permission. The trojan runs on every Windows startup. Sooner or later Wobmat will destroy the system preventing it from booting and working properly.


Related files: deltree.exe, Popup.exe, terminate.exe, wupdmgr.exe, 222.exe, internet.bat, bt[X].bat, temp.bat, tweaks.reg

Wombat properties:
• Hides from the user
• Stays resident in background

Automatic Wombat removal:

remover for Wombat

Wombat manual removal:

Kill processes:
deltree.exe, popup.exe, terminate.exe, wupdmgr.exe, 222.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mike3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mixed1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mixed2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mixed3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\terminate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\twitch
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\DoNotAllowExceptions=0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\DisableRegistryTools=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr=1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCDBurning=1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window Title=UNLUCKY
Delete files:
deltree.exe, popup.exe, terminate.exe, wupdmgr.exe, 222.exe, internet.bat, bt[X].bat, temp.bat, tweaks.reg
Misc:
[X] is a combination of random digits.

File location (may vary):
bt[X].bat - C:\Windows\Temp or C:\Winnt\Temp
terminate.exe, 222.exe, internet.bat - C:\Windows\mui or C:\Winnt\mui
deltree.exe, temp.bat - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32

Other programs to remove Wombat:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 27/09/06
Information updated: 27/09/06

Additional resources related to Wombat:

Attention: If you know or you have a website or page about Wombat removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Wombat parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: