Whilokii 1.0.0

Whilokii 1.0.0

Known Toolbar

by Yontoo Technology, Inc.

What is Whilokii 1.0.0?

Whilokii 1.0.0 is software application developed by Yontoo Technology, Inc.. It is most commonly found on computers running Windows 7 with nearly 63.91% of installations running this operating system. Whilokii 1.0.0's installer is typically 1.00 MB in size and installs around 8 files.

Whilokii 1.0.0 is most popular in the United States with 52.27% of installations residing in this country.

About Whilokii 1.0.0?

Whilokii is a web browser adware application that functions as a toolbar and web extension. The primary purpose of the web extension is to seize control of the user's browser in order to alter the search provider and direct web searches to a specific search engine with which the publisher has a revenue relationship. The toolbar employs a variety of tactics to increase the likelihood of user clicks on sponsored advertising through search, including injecting context ads, pop-ups, and pop-unders. It also alters the browser's default home page and search provider, as well as the address bar and 'new tab' functionality. Additionally, Whilokii adds alternative error pages and functionality to protect search and home page settings. Whilokii is often distributed as part of software bundles containing potentially unwanted apps, such as Quick Downloader's wrapper of legitimate software, AppWork's install of JDownloader, and JumpyApps' various compression software installations.

Multiple virus scanners have detected malware in Whilokii 1.0.0.

updateWhilokii.exe (MD5: bad42b9d0f363c24988748c75cf13748) has been flagged by 22 scanners:
Scanner Software Result
Comodo Security Application.Win32.Whilo.uy
Dr.Web Adware.Plugin.100
ESET-NOD32 a variant of MSIL/BrowseFox.A
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Sophos SuperWeb
TrendMicro-HouseCall TROJ_GEN.F47V0927
VIPRE Antivirus Yontoo (fs)
Agnitum Outpost PUA.Agent!
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
Fortinet FortiGate Adware/Agent
IKARUS anti.virus not-a-virus:AdWare.Win32.Agent
Jiangmin Adware/Agent.izz
K7 AntiVirus Unwanted-Program ( 00454f261 )
K7GW Unwanted-Program ( 00454f261 )
Kaspersky not-a-virus:AdWare.Win32.Agent.ahbx
Malwarebytes PUP.Optional.Whilokii.A
McAfee Artemis!5EE22140F5D0
McAfee-GW-Edition Artemis!5EE22140F5D0
NANO AntiVirus Riskware.Win32.Agent.cuenda
SUPERAntiSpyware Adware.BrowseFox/Variant
Symantec Trojan.ADH.2
Vba32 AntiVirus AdWare.Agent
WhilokiiBHO.dll (MD5: 5ee22140f5d0cf059489d3ce3e0a57b7) has been flagged by 22 scanners:
Scanner Software Result
Agnitum Outpost PUA.Agent!
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
Comodo Security Application.Win32.Altbrowse.AK
Dr.Web Trojan.BPlug.28
ESET-NOD32 a variant of Win32/BrowseFox.F
Fortinet FortiGate Adware/Agent
IKARUS anti.virus not-a-virus:AdWare.Win32.Agent
Jiangmin Adware/Agent.izz
K7 AntiVirus Unwanted-Program ( 00454f261 )
K7GW Unwanted-Program ( 00454f261 )
Kaspersky not-a-virus:AdWare.Win32.Agent.ahbx
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
Malwarebytes PUP.Optional.Whilokii.A
McAfee Artemis!5EE22140F5D0
McAfee-GW-Edition Artemis!5EE22140F5D0
NANO AntiVirus Riskware.Win32.Agent.cuenda
Sophos Generic PUA EJ
SUPERAntiSpyware Adware.BrowseFox/Variant
Symantec Trojan.ADH.2
TrendMicro-HouseCall TROJ_GEN.F47V0228
Vba32 AntiVirus AdWare.Agent
VIPRE Antivirus Adware.Agent

Software Behaviors

Services:
  • updateWhilokii.exe runs as a service named 'Update Whilokii' (Update Whilokii).

Software Details

URL:
https://whilokii.net/support
Support:
https://mailto:
Installation path:
C:\Program Files\Whilokii
Uninstaller:
C:\Program Files\Whilokii\Whilokiiuninstall.exe
Size:
1.00 MB
Language:
English

Whilokii 1.0.0 Executable Details

Primary executable:
updateWhilokii.exe
Name:
Whilokii 1.0.0
Path:
C:\Program Files\Whilokii\updateWhilokii.exe
MD5:
bad42b9d0f363c24988748c75cf13748
SHA-1:
SHA-256:
Files installed by Whilokii 1.0.0
File Type Filename MD5
DLL
5cad5792bb209694db6e36baa2ca83ea
DLL
6351ce60a355e36a1842edc3a8337739
EXE
0b86536bba2a922f5f32ad1792d8a03b
DLL
ee937d637efefa125cd285155cf2f16c
EXE
bad42b9d0f363c24988748c75cf13748
DLL
5ee22140f5d0cf059489d3ce3e0a57b7
EXE
c4dcf90f9d2a983a5de511f0fede4ed3
EXE
d024236b5251aff4a0be44fa96a60bb8