Home Malware Programs Browser Hijackers Wow Search

Wow Search

Posted: March 24, 2014

Threat Metric

Ranking: 2,424
Threat Level: 5/10
Infected PCs: 153,501
First Seen: March 24, 2014
Last Seen: October 16, 2023
OS(es) Affected: Windows


Wow Search Screenshot 1Wow Search is both a search site and associated browser toolbar that promotes Wow Search, along with other unwanted products and, in some cases, even threats. Even though malware experts have verified that Wow Search's current search results are safe to browse, Wow Search's overall bad reputation and tendency to be associated with negative browser add-ons makes the removal of all Wow Search software a default recommendation for your PC's safety. Some variants of Wow Search software may disable your access to browser add-on settings and may even be installed with other, equally unwanted software. Using general anti-malware software is recommended for overcoming these common issues, both for Wow Search and for similar browser-hijacking search engines.

Wow Search – a Search Site that Scarcely 'Wows' Its Users

Found at wow.utop.it, Wow Search is a search site that scrapes content from other search engines to fuel its results. While this isn't illegal, there are no benefits to using Wow Search's search engine, nor do malware experts recommend installing the software associated with Wow Search. The latter warning is particularly relevant, due to recently-identified browser-hijacking campaigns that are associated with Wow Search. These attacks are coordinated by Potentially Unwanted Programs that are installed through bundles with other software and files, such as technical user manuals for electronics. Naturally, scanning any files downloaded from a potentially unsafe source is the most immediate defense that malware experts can recommend.

Wow Search add-ons have been identified with a variety of generic names, such as 'Plugins,' and also may be bundled with other programs like 'Download 0.1.7' or EZ Dropbox. In some cases, these programs also may include other, beneficial features along with their redirects to Wow Search. In others, resetting your homepage or search engine to Wow Search, or loading an additional search bar for Wow Search, is the only function that the add-ons possess. Based on the patterns of previous incidents, malware researchers estimate that Chrome and Firefox browsers are more propense to being targeted by these browser hijacks.

Finding a Search Engine Utopia Away from Wow Search's Utop.it

Though there's no harm in browsing the Web with Wow Search, neither are there any advantages to using its search services, or letting PUPs redirect your browser to Wow Search automatically. Since the latter function may be a security issue, malware researchers recommend removing all unwanted Wow Search add-ons from any browser modified by them. Wow Search has a history of using various methods to block the removal of its software, and you may need anti-malware utilities to render deleting Wow Search toolbars as efficient and painless as possible.

No matter how hard they are to uninstall, most browser hijackers and unwanted add-ons are installed through the incidental efforts of the compromised PC's user. Sites that haven't been verified for your safety never should be trusted for file downloads. However, if there are no alternative resources available, you can protect your PC from Wow Search installers, as long as you scan any suspicious files with appropriate and up-to-date security software before launching them.

Wow Search Screenshot 2Wow Search Screenshot 3

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\yvd_firefox_se.exe File name: yvd_firefox_se.exe
Size: 1.52 MB (1525193 bytes)
MD5: 4249668af1c02218c7080769dc9a481e
Detection count: 9,155
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\yvd_firefox_se.exe
Group: Malware file
Last Updated: July 19, 2023
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\yvd_firefox_se.exe File name: yvd_firefox_se.exe
Size: 1.51 MB (1517522 bytes)
MD5: 3da0526556d942cabe180397c9e3c0a7
Detection count: 4,080
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\SystemRestore\FRStaging\ProgramData\yvd_firefox_se.exe
Group: Malware file
Last Updated: April 28, 2023
C:\ProgramData\yvd_ie_se.exe File name: yvd_ie_se.exe
Size: 837.53 KB (837536 bytes)
MD5: 6a99c2d85398302a4c75283076d99176
Detection count: 3,949
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\yvd_ie_se.exe
Group: Malware file
Last Updated: November 6, 2022
%ALLUSERSPROFILE%\yvd_chrome_se.exe File name: yvd_chrome_se.exe
Size: 2.03 MB (2032309 bytes)
MD5: a8e0f980082c683278ad862b52b12022
Detection count: 3,295
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 12, 2020
C:\ProgramData\yvd_firefox_se.exe File name: yvd_firefox_se.exe
Size: 1.52 MB (1529534 bytes)
MD5: f1a3227d3d9e416e4631e64f3ada9d80
Detection count: 3,197
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\yvd_firefox_se.exe
Group: Malware file
Last Updated: February 26, 2023
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\yvd_chrome_se.exe File name: yvd_chrome_se.exe
Size: 2.02 MB (2029908 bytes)
MD5: eb9cdfd9b0f9e0887a944330942143ab
Detection count: 3,075
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\SystemRestore\FRStaging\ProgramData\yvd_chrome_se.exe
Group: Malware file
Last Updated: January 1, 2022
%ALLUSERSPROFILE%\yvd_firefox_se.exe File name: yvd_firefox_se.exe
Size: 1.52 MB (1525199 bytes)
MD5: c2c05f5d2659aeb5455b4ff39b9fe210
Detection count: 2,113
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 12, 2020
%ALLUSERSPROFILE%\yvd_chrome_se.exe File name: yvd_chrome_se.exe
Size: 2.03 MB (2032299 bytes)
MD5: 842a62fc4678285121c7d25a1fa9da25
Detection count: 1,342
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 28, 2023
%ALLUSERSPROFILE%\yvd_firefox_se.exe File name: yvd_firefox_se.exe
Size: 1.52 MB (1525198 bytes)
MD5: 0201a7a7429d04fe39471cc4372da747
Detection count: 881
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 12, 2020
C:\ProgramData\yvd_firefox_se.exe File name: yvd_firefox_se.exe
Size: 1.52 MB (1524690 bytes)
MD5: e79dc6c96d9ada9f2f7eaa95b9d023fe
Detection count: 393
File type: Executable File
Mime Type: unknown/exe
Path: C:\ProgramData\yvd_firefox_se.exe
Group: Malware file
Last Updated: October 26, 2022
%ALLUSERSPROFILE%\yvd_chrome_se.exe File name: yvd_chrome_se.exe
Size: 1.29 MB (1294727 bytes)
MD5: 3e4efcaa9721188ae5fe7de6f3407f76
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 28, 2023
%ALLUSERSPROFILE%\yvd_ie_se.exe File name: yvd_ie_se.exe
Size: 108.92 KB (108929 bytes)
MD5: 7661af702adbc6ce9fdfe8c491aadef1
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 28, 2023
%ALLUSERSPROFILE%\yvd_ie_se.exe File name: yvd_ie_se.exe
Size: 11.03 KB (11035 bytes)
MD5: 982d417931f4662145123776d84b27e6
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 26, 2014
%ALLUSERSPROFILE%\yvd_firefox_se.exe File name: yvd_firefox_se.exe
Size: 2.75 KB (2758 bytes)
MD5: c2c7142d816c5413bf13c5552761001a
Detection count: 62
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 26, 2014
%ALLUSERSPROFILE%\yvd_chrome_se.exe File name: yvd_chrome_se.exe
Size: 4.13 KB (4138 bytes)
MD5: b5e2f894a23ee2910b5d6e6d7c34e366
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 26, 2014
%ALLUSERSPROFILE%\yvd_ie_se.exe File name: yvd_ie_se.exe
Size: 11.36 KB (11360 bytes)
MD5: c8f3fd40c03749d30d9cb6b47e86059c
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 26, 2014
%ALLUSERSPROFILE%\yvd_firefox_se.exe File name: yvd_firefox_se.exe
Size: 8.52 KB (8520 bytes)
MD5: 89ab762141cefa4151135a6692f7e673
Detection count: 51
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 26, 2014
%ALLUSERSPROFILE%\yvd_chrome_se.exe File name: yvd_chrome_se.exe
Size: 11.36 KB (11360 bytes)
MD5: 7a785cfb58c47dea7a6d6cd4875bbb16
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 26, 2014
%ALLUSERSPROFILE%\yvd_ie_se.exe File name: yvd_ie_se.exe
Size: 7.12 KB (7128 bytes)
MD5: 0172288bda3ee544518b30f740a3d0e0
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: March 26, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathhttp_utop.it_0.localstoragehttp_utop.it_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes\{9bb2c1cc-4a7d-4cd5-bce9-0ca5f9ff8391}SOFTWARE\Microsoft\Internet Explorer\DOMStorage\utop.itSoftware\Microsoft\Internet Explorer\SearchScopes\{9bb2c1cc-4a7d-4cd5-bce9-0ca5f9ff8391}SOFTWARE\wow searchSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9bb2c1cc-4a7d-4cd5-bce9-0ca5f9ff8391}SOFTWARE\Wow6432Node\wow search

Additional Information

The following directories were created:
%PROGRAMFILES%\wow search%PROGRAMFILES(x86)%\wow search
The following URL's were detected:
res.utop.itwow.utop.it
Loading...