Wowcraft.c is a trojan that monitors opened windows and steals user login names and passwords related to popular computer games "World of Warcraft" and "The Legend of Mir". Gathered data is transferred to a predefined remote host. Wowcraft.c can also terminate running security-related software and log user keystrokes. The trojan automatically runs on every Windows startup.
Wowcraft.c properties:
• Logs keystrokes
• Connects itself to the internet
• Hides from the user
• Stays resident in background
We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.
By Downloading any provided Anti-spyware software to remove Wowcraft.c you agree to our
privacy policy and
agreement of use.
Wowcraft.c manual removal:
Kill processes:
debugprogram.exe, exert.exe, lsass.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\top=%Windows%\lsass.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command\(Default)=C:\Program Files\Internet Explorer\intexplore.com %1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)=WindowFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)=%Windir%\exert.exe "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ftp\Shell\Open\Command\(Default)=C:\Program Files\Internet Explorer\intexplore.com %1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htmlfile\Shell\Open\Command\(Default)=C:\Program Files\Common Files\intexplore.pif %1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\htmlfile\Shell\Open\Command\(Default)=C:\Program Files\Internet Explorer\intexplore.com -nohome
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\HTTP\Shell\Open\Command\(Default)=C:\Program Files\Common Files\intexplore.pif -nohome
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowFiles\Shell\Open\Command\(Default)=WindowFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowFiles\Shell\Open\Command\(Default)=%Windir%\exert.exe "%1" %*
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\intexplore.pif
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Check_Associations=no
Delete files:debugprogram.exe, exert.exe, lsass.exe, dxdiag.com, intexplore.com, msconfig.com, regedit.com, intexplore.pif
Misc:exert.exe, lsass.exe - C:\Windows or C:\Winnt
intexplore.pif - C:\Program Files\Common Files
intexplore.com - C:\Program Files\Internet Explorer
debugprogram.exe - C:\Windows\Debug or C:\Winnt\Debug
dxdiag.com, msconfig.com, regedit.com - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Post Comment: