Elex Hijacker

Elex Hijacker Description

The Elex Hijacker is a Web browser hijacker that may take over a Web browser, change its homepage and other settings and prevent computer users from restoring their Web browser to its default setting. The Elex Hijacker may be associated with a variety of other unwanted symptoms. The main reason that makes the Elex Hijacker is considered a browser hijacker is because its main purpose is to take over a Web browser to force computer users to view certain websites repeatedly and open new Web browser windows and tabs while the computer users attempt to use their computers. The Elex Hijacker is promoted as a useful Web browser extension or add-on. However, PC security researchers have determined that the Elex Hijacker does not offer any useful or beneficial service. Rather, the Elex Hijacker is designed to make money at the expense of computer users by displaying advertisements or forcing them to visit websites related to their affiliate websites.

The Elex Hijacker may Expose Your Computer to Threatening Content

One of the main problems related to the Elex Hijacker is that computer users don't really have any control over the websites that their Web browser forces them to visit. This may cause computers to become infected with threats or other low-level threats as a result of the Elex Hijacker redirects or pop-ups. Essentially, the Elex Hijacker itself is a low-level threat, but various pop-up messages and affiliated websites may expose your computer to more threatening unwanted content. Another issue with the Elex Hijacker is that it may deliver large volumes of advertising content to computer users in the form of banners, inserted links, pop-up advertisements, and other unwanted advertisements added to the websites viewed on the affected Web browser. The Elex Hijacker may cause important performance issues on affected computers. If the Elex Hijacker is installed on your Web browser, this may increase the probability of crashing, freezing or a slower performance.

How the Elex Hijacker may Infect a Computer

One of the ways in which the Elex Hijacker may be distributed is by using typical threat deliver methods. Because of this, you should be well protected from the Elex Hijacker if your computer is safeguarded against threats, or if you have taken steps to avoid threats when browsing the Web. However, browser hijackers such as the Elex Hijacker may pass anti-malware protection. This is because the Elex Hijacker and other low-level threats also may be distributed by bundling them with other software. Computer users may be confused or surprised by the sudden appearance of the Elex Hijacker on their Web browser, which may happen right after they have installed software on their computers. However, the software is rarely the culprit. Rather, it is not uncommon for free programs to be bundled with components like the Elex Hijacker, often advertised as useful Web browser add-ons or extensions. Once the Elex Hijacker enters a computer, it may take the form of a browser toolbar or extension and interfere with the affected Web browser constantly.

Why the Elex Hijacker may be Bundled with Other Software

The most common way of distributing the Elex Hijacker and similar low-level threats is by bundling them with other software. Con artists may take popular free software and use custom installers or bundlers to include the Elex Hijacker or similar components along with the installation of that software. In most cases, the custom installers may be created to make it hard for computer users to realize that the Elex Hijacker or another unwanted component is being installed. The Elex Hijacker may be set to be installed by default, requiring computer users to opt out. The option to opt out of installing the Elex Hijacker also may be hidden behind a 'Custom Installation' or 'Advanced Installation' options. Computer users are advised to pay careful attention to the entire set up process when installing any new software.

Aliases: Adware ( 004d2a5f1 ) [K7GW], ADW_ELEX [TrendMicro-HouseCall], Artemis!5C76D5C030CB [McAfee], Artemis!Trojan [McAfee-GW-Edition], PUP/Win32.Generic [AhnLab-V3], PUP/XTab [Panda], Riskware/Elex [Fortinet], Trojan.Win32.Generic!BT [VIPRE] and Win32/ELEX.FJ potentially unwanted [ESET-NOD32].

Infected with Elex Hijacker? Scan Your PC

Download SpyHunter's Spyware Scanner
to Detect Elex Hijacker
* SpyHunter's scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware removal tool to remove the malware threats. Read more on SpyHunter. If you no longer wish to have SpyHunter installed on your computer, follow these steps to uninstall SpyHunter.

Security Doesn't Let You Download SpyHunter or Access the Internet?


Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in "Safe Mode with Networking" and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

Infection Statistics


Our MalwareTracker shows malware activity across the world. Explore real-time data of Elex Hijacker outbreaks and other threats from global to local level.

File System Details

Elex Hijacker creates the following file(s):
# File Name Size MD5 Detection Count
1 %ALLUSERSPROFILE%\WindowsMangerProtect\ProtectWindowsManager.exe 535,936 ba4da4299310f4a54cbba25221072d70 26,296
2 %PROGRAMFILES%\SupTab\Loader32.exe 64,000 d46415cd75dda09f0a17d2fda2235cb0 4,241
3 %LOCALAPPDATA%\simple_new_tab\simple_new_tab.dll 213,504 9d43dc984217b861a35cd38e2b4e0503 4,224
4 %USERPROFILE%\AppData\Everything\ServiceEverything.exe 233,984 7efadb498146583beeed83eeb43e4456 3,359
5 %LOCALAPPDATA%\AMD\amd.exe 120,320 7568abb7d1edfafeaf4cd87213e27e27 3,081
6 %USERPROFILE%\AppData\Everything\Everything.exe 798,720 048c3abbfd6c3d729f1f8f0b7fc15aeb 3,062
7 %PROGRAMFILES(x86)%\Gubed\GubedZL.dll 119,808 248d864eac6fe685205194de0db0890c 2,218
8 %APPDATA%CheckRun22find.exe 102,912 0048a144c614babfe9df0496264d3d46 2,173
9 %LOCALAPPDATA%\terana\terana.dll 908,288 a999ec5c40f36f31f75a57cd6750ae9b 1,991
10 %PROGRAMFILES(x86)%\SupTab\SearchProtect64.dll 96,768 f73b82c5f4e23f5e543fc86c5ee02558 1,821
11 %PROGRAMFILES(x86)%\Stoviing\PptPrv.dll 273,920 2c4c3627e882aea2ae2725807678c1ba 1,782
12 %ALLUSERSPROFILE%\BwinpB\WFini.exe 569,344 189920d9188cd906831cc388048dead0 1,580
13 %PROGRAMFILES%\Gubed_WMI\Gubed_WMI.exe 108,544 ed276ff494869ef1d33ae82d40963b95 1,439
14 %ALLUSERSPROFILE%\SoeasyHelper\Helper.exe 182,424 d07d1c4d618d22e5879bc2525564ff75 1,163
15 %PROGRAMFILES%\Plesege\Ckaletionbuilder.dll 297,472 0456de65ff271932229d868d623a17b6 1,122
More files

Registry Details

Elex Hijacker creates the following registry entry or registry entries:
HKEY..\..\..\..{RegistryKeys}
Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
SOFTWARE\Wow6432Node\V9
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WPM
SOFTWARE\Wow6432Node\supWPM
SOFTWARE\supWPM
SYSTEM\ControlSet002\services\Wpm
SYSTEM\CurrentControlSet\services\eventlog\Application\Wpm
SYSTEM\CurrentControlSet\services\Wpm
SOFTWARE\Wpm
SYSTEM\ControlSet001\services\eventlog\Application\WindowsProtectManger
SYSTEM\ControlSet002\services\eventlog\Application\WindowsProtectManger
SYSTEM\CurrentControlSet\services\eventlog\Application\WindowsProtectManger
SYSTEM\ControlSet001\services\WindowsProtectManger
SYSTEM\ControlSet002\services\WindowsProtectManger
SYSTEM\CurrentControlSet\services\WindowsProtectManger
SOFTWARE\Wow6432Node\supWindowsMangerProtect
SOFTWARE\supWindowsMangerProtect
SYSTEM\CurrentControlSet\services\eventlog\Application\WindowsMangerProtect
SYSTEM\CurrentControlSet\services\WindowsMangerProtect
SYSTEM\ControlSet002\services\WindowsMangerProtect
SYSTEM\ControlSet001\services\IHProtect Service
SYSTEM\ControlSet002\services\IHProtect Service
Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
SOFTWARE\Wow6432Node\IHProtect
SOFTWARE\IHProtect
SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions, value: searchengine@gmail.com
SOFTWARE\Mozilla\Firefox\Extensions, value: searchengine@gmail.com
SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions, value: istart_ffnt@gmail.com
SOFTWARE\Wow6432Node\FFPluginHp
SOFTWARE\FFPluginHp
SYSTEM\CurrentControlSet\services\eventlog\Application\WdsManPro
SYSTEM\ControlSet002\services\eventlog\Application\WdsManPro
SYSTEM\ControlSet001\services\WdsManPro
SYSTEM\ControlSet002\services\WdsManPro
SYSTEM\CurrentControlSet\services\WdsManPro
SOFTWARE\Mozilla\Firefox\Extensions, value: yahooprotected@gmail.com
SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions, value: yahooprotected@gmail.com
SYSTEM\ControlSet002\services\TDataSvr
SYSTEM\CurrentControlSet\services\TDataSvr
SYSTEM\ControlSet001\services\eventlog\Application\WdMan
SYSTEM\ControlSet002\services\eventlog\Application\WdMan
SYSTEM\CurrentControlSet\services\eventlog\Application\WdMan
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Wintaske
Software\1stTool
Software\Wow6432Node\1stTool
SYSTEM\CurrentControlSet\Services\Nmclogservice
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Nimeckreelule Log
SYSTEM\ControlSet002\services\cegushHelpersr
SYSTEM\ControlSet001\services\cegushHelpersr
SYSTEM\CurrentControlSet\services\cegushHelpersr
SOFTWARE\Wow6432Node\{E6276374-DE18-4AA5-A365-9016A2F98A2D}
SOFTWARE\{E6276374-DE18-4AA5-A365-9016A2F98A2D}
SOFTWARE\Microsoft\Tracing\WinTaske_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\WinTaske_RASAPI32
SOFTWARE\Wow6432Node\{8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
SOFTWARE\Classes\Local Settings\ms-ptid-key, value: {8C4CE252-7DB2-4F8E-8E76-BAD0E5826A83}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks, value: {6710C780-E20E-4C49-A87D-321850ED3D7C}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dahashhecech Reports
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Ghmersevversp Monitor
SYSTEM\ControlSet001\services\SoEasySvc
SYSTEM\ControlSet002\services\SoEasySvc
SYSTEM\CurrentControlSet\services\SoEasySvc
SYSTEM\CurrentControlSet\services\ThjmonitorTerkaystazerch.exe
SYSTEM\ControlSet002\services\ThjmonitorTerkaystazerch.exe
SYSTEM\ControlSet001\services\ThjmonitorTerkaystazerch.exe
SYSTEM\ControlSet001\services\SoEasyHelper
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Philitheraniget Agent
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sheerwardposoing Renew
SYSTEM\CurrentControlSet\Services\winsaber
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: MuroghfibchCloud
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: MuroghfibchCloud
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Muroghfibch Cloud
SYSTEM\ControlSet002\Services\MuroghfibchCloud
SYSTEM\CurrentControlSet\Services\MuroghfibchCloud
SYSTEM\ControlSet001\Services\MuroghfibchCloud
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Johicultdruvasp Host
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UnregisterNonABICompliantCodeRange
SYSTEM\CurrentControlSet\services\RvsmppFrl.exe
SYSTEM\ControlSet002\Services\RvsmppFrl.exe
SOFTWARE\Microsoft\Tracing\WinTaske_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\WinTaske_RASMANCS
SOFTWARE\WOW6432Node\Mozilla\Firefox\Extensions, value: arthurj8283@gmail.com
SOFTWARE\Mozilla\Firefox\Extensions, value: arthurj8283@gmail.com
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ChelfNotify Task
SYSTEM\ControlSet001\Services\Coerlasy
SYSTEM\ControlSet002\Services\Coerlasy
SYSTEM\CurrentControlSet\Services\Coerlasy
SYSTEM\CurrentControlSet\services\Suzocult
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: Suzocult
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: Suzocult
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Zerhiedtulert Renew
SYSTEM\CurrentControlSet\Services\Dowitherfelery
SYSTEM\ControlSet002\Services\Dowitherfelery
SYSTEM\ControlSet001\Services\Dowitherfelery
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Qokaghtplerfied Manager
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Gredorymermely Renew
SYSTEM\CurrentControlSet\Services\Coalerly
SYSTEM\ControlSet002\services\Coalerly
SYSTEM\ControlSet001\Services\Grzerck
SYSTEM\ControlSet002\Services\Grzerck
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Jujasy Core
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: WinSAPSvc
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: ArcherGroupEx
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: ArcherGroupEx
SOFTWARE\Wow6432Node\WinArcher
SOFTWARE\WinArcher
SYSTEM\ControlSet001\Services\drsiyseuch
SYSTEM\ControlSet002\Services\drsiyseuch
SYSTEM\CurrentControlSet\Services\drsiyseuch
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Dropige Renew
SOFTWARE\{84416237-6490-494D-9AD6-4994DD978971}
SOFTWARE\Wow6432Node\{84416237-6490-494D-9AD6-4994DD978971}
Software\Microsoft\Installer\UpgradeCodes\59F9B1BAE01B311409E978015D938349
Software\Microsoft\Installer\Features\3CADD814C61E2C745BEFF4CBBAE0010D
Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
SYSTEM\CurrentControlSet\services\UvConv
SYSTEM\CurrentControlSet\services\ed2kidle
SYSTEM\ControlSet001\services\UvConv
SYSTEM\ControlSet002\services\UvConv
SYSTEM\ControlSet001\services\ed2kidle
SYSTEM\ControlSet002\services\ed2kidle
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Stuteringghewish Agent
SYSTEM\ControlSet001\services\Pidlyclerpaing
SYSTEM\ControlSet002\services\Pidlyclerpaing
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Reubecharunege Adapter
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uzesyghojet Debuger
SYSTEM\CurrentControlSet\Services\Aterzetpegesh
SYSTEM\ControlSet002\Services\Aterzetpegesh
SYSTEM\ControlSet001\Services\Aterzetpegesh
SYSTEM\ControlSet002\services\Mihethoderly
SYSTEM\CurrentControlSet\services\Mihethoderly
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: Doackarerviing
SYSTEM\CurrentControlSet\Services\Doackarerviing
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: Qusowardhsaty
SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: Qusowardhsaty
SYSTEM\ControlSet001\Services\Qusowardhsaty
SYSTEM\ControlSet002\Services\Qusowardhsaty
SYSTEM\CurrentControlSet\Services\Qusowardhsaty
SYSTEM\CurrentControlSet\services\Zerdgeghevse
SYSTEM\ControlSet002\services\Zerdgeghevse
SYSTEM\CurrentControlSet\services\Mosusypososy
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Ckowry Monitor
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sibele Core
SYSTEM\CurrentControlSet\services\Atoverk
SYSTEM\ControlSet001\services\Atoverk
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Atevotionpherjety Provider
SYSTEM\ControlSet001\Services\Ploseent
SYSTEM\ControlSet002\Services\Ploseent
System\CurrentControlSet\Services\Ploseent
SOFTWARE\b`nl{y
SYSTEM\ControlSet001\services\Paradom
SYSTEM\ControlSet002\services\Paradom
SYSTEM\CurrentControlSet\services\Paradom
SOFTWARE\GooNetSo
SOFTWARE\Wow6432Node\GooNetSo
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: WinSnare
SYSTEM\ControlSet001\services\eventlog\Application\WinSnare
SYSTEM\ControlSet002\services\eventlog\Application\WinSnare
SYSTEM\CurrentControlSet\services\eventlog\Application\WinSnare
SYSTEM\ControlSet001\services\GubedZL
SYSTEM\ControlSet002\services\GubedZL
SYSTEM\CurrentControlSet\services\GubedZL
SYSTEM\ControlSet001\services\WinSnare
SYSTEM\ControlSet002\services\WinSnare
SYSTEM\CurrentControlSet\services\WinSnare
Software\WinSnare
SOFTWARE\Wow6432Node\xvb`lj
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Atervuther Launcher
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Juqgehuwuk Cache
SYSTEM\ControlSet002\services\Cluseywreph
SYSTEM\ControlSet001\services\Cluseywreph
SYSTEM\ControlSet002\services\Nipuytersary
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Siutainbamersp Update
SYSTEM\CurrentControlSet\Services\Ckemghrajock
SYSTEM\ControlSet002\services\Ckemghrajock
SYSTEM\ControlSet001\services\Ckemghrajock
SYSTEM\ControlSet002\Services\Fenghtchiqesy
SYSTEM\ControlSet001\Services\Fenghtchiqesy
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Gerutwderge Configuration
SYSTEM\CurrentControlSet\Services\Sufiphegesh
SYSTEM\ControlSet002\Services\Sufiphegesh
SYSTEM\ControlSet001\Services\Sufiphegesh
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Wuwotion Schedule
SYSTEM\ControlSet002\Services\Ghooenthlerle
SYSTEM\CurrentControlSet\Services\Ghooenthlerle
SYSTEM\ControlSet001\Services\Ghooenthlerle
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: Ghooenthlerle
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: Ghooenthlerle
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: Liviwardjetit
SYSTEM\ControlSet001\Services\Liviwardjetit
SYSTEM\ControlSet002\Services\Liviwardjetit
SYSTEM\CurrentControlSet\Services\Liviwardjetit
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Plcult Helper
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Ploruty
SOFTWARE\BDE27E550C179F628994EC554C87211A
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Reuhyreiluty Launcher
SOFTWARE\Wow6432Node\BDE27E550C179F628994EC554C87211A
SOFTWARE\Terdickjipuward
SOFTWARE\Wow6432Node\Terdickjipuward
SOFTWARE\Reoceingberkupy
SOFTWARE\Wow6432Node\Reoceingberkupy
SOFTWARE\Deshicuge
SOFTWARE\Wow6432Node\Deshicuge
SOFTWARE\Theralyckitain
SOFTWARE\Wow6432Node\Theralyckitain
SOFTWARE\Atuqward
SOFTWARE\Wow6432Node\Atuqward
Software\deskapp
SOFTWARE\Hihgereuferle
SOFTWARE\Wow6432Node\Hihgereuferle
SOFTWARE\Wow6432Node\Reofother
SOFTWARE\Reofother
Software\6CBC6BAE34E569F53989853DD6DD5BC4
SOFTWARE\Wow6432Node\6CBC6BAE34E569F53989853DD6DD5BC4
SOFTWARE\Wow6432Node\Germush
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Kibash Log
SOFTWARE\Therwogh
SOFTWARE\Wow6432Node\Microsoft\Tracing\BikaQ_RASMANCS
SYSTEM\ControlSet001\services\Kyubey
SYSTEM\ControlSet002\services\Kyubey
SOFTWARE\Kametgregery
SOFTWARE\Wow6432Node\Kametgregery
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: SNARE
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Kerphcobuly Provider
SOFTWARE\Acerlyatuzet
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: WANARE
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: WANARE
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: NPASRE
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: NPASRE
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: VNASRE
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: VNASRE
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: ANSARE
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: ANSARE
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: SANARE
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: SANARE
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: appmodels
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: appmodels
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: BIT
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: BIT
SYSTEM\ControlSet001\services\WinAppSvr
SYSTEM\ControlSet002\services\WinAppSvr
SYSTEM\CurrentControlSet\services\WinAppSvr
SYSTEM\ControlSet001\services\CWASRE
SYSTEM\ControlSet001\services\eventlog\Application\CWASRE
SYSTEM\ControlSet002\services\CWASRE
SYSTEM\ControlSet002\services\eventlog\Application\CWASRE
SYSTEM\CurrentControlSet\services\CWASRE
SYSTEM\CurrentControlSet\services\eventlog\Application\CWASRE
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Mavoght Nodifier
SOFTWARE\Reutodom
SOFTWARE\Wow6432Node\Reutodom
SOFTWARE\Reerqughtghividom
SOFTWARE\WOW6432Node\Stemoght
SOFTWARE\Stemoght
SOFTWARE\WOW6432Node\vupesh.exe
SOFTWARE\vupesh.exe
SOFTWARE\xcatersy.exe
SOFTWARE\WOW6432Node\xgheray.exe
SOFTWARE\xgheray.exe
SYSTEM\ControlSet001\Services\Kitty
SYSTEM\ControlSet002\Services\Kitty
SYSTEM\CurrentControlSet\Services\EventLog\Application\SANARE
SYSTEM\ControlSet001\Services\EventLog\Application\SANARE
SYSTEM\ControlSet002\Services\EventLog\Application\SANARE
SOFTWARE\WOW6432Node\Jogokchujale
SOFTWARE\WOW6432Node\Ercshzudiward
SOFTWARE\Ercshzudiward
SOFTWARE\WOW6432Node\Ghergupy
SOFTWARE\Ghergupy
SOFTWARE\WOW6432Node\Jrgegheweried
SOFTWARE\Jrgegheweried
SOFTWARE\Nigeghoesp
SYSTEM\ControlSet002\Services\NPASRE
SYSTEM\ControlSet001\Services\EventLog\Application\SNARE
SYSTEM\ControlSet002\Services\EventLog\Application\SNARE
SYSTEM\CurrentControlSet\Services\EventLog\Application\SNARE
SOFTWARE\Rierckkadery
SOFTWARE\Wow6432Node\Rierckkadery
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Drgitrevush Log
Software\Google\Chrome\PreferenceMACs\feloskpchphipeph
SOFTWARE\yaupdcache.exe
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Gerfety Renew
SYSTEM\CurrentControlSet\services\terana
SYSTEM\ControlSet002\services\terana
SYSTEM\ControlSet001\services\terana
Software\Wow6432Node\4B48608B6A20F0E324F966C1A889E3E2
Software\4B48608B6A20F0E324F966C1A889E3E2
Software\Wow6432Node\Google\Chrome\PreferenceMACs\conaingtitckly
Software\Google\Chrome\PreferenceMACs\conaingtitckly
Software\Wow6432Node\Google\Chrome\PreferenceMACs\cerloryatilutaincerges
Software\Google\Chrome\PreferenceMACs\cerloryatilutaincerges
Software\Wow6432Node\Google\Chrome\PreferenceMACs\arewtanvoghkidient
Software\Google\Chrome\PreferenceMACs\arewtanvoghkidient
SOFTWARE\dereph.exe
SOFTWARE\Wow6432Node\dereph.exe
SOFTWARE\Wow6432Node\Zosyweriph
SOFTWARE\Zosyweriph
SOFTWARE\Tobilezijasp
SOFTWARE\Wow6432Node\Tobilezijasp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Nogisphaniing Log
SOFTWARE\Jqaentanonuph
SOFTWARE\Wow6432Node\Jqaentanonuph
SOFTWARE\FlyingBird
SOFTWARE\Wow6432Node\FlyingBird
SOFTWARE\MicroRay
SOFTWARE\Wow6432Node\MicroRay
Software\Google\Chrome\PreferenceMACs\wutelereeacultgrujent
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Ghivedom Schedule
Software\Wow6432Node\Google\Chrome\PreferenceMACs\inercktwitainrtach
Software\Google\Chrome\PreferenceMACs\inercktwitainrtach
SYSTEM\ControlSet001\services\eventlog\Application\terana
SYSTEM\ControlSet002\services\eventlog\Application\terana
SOFTWARE\Wow6432Node\Microsoft\Tracing\ZaamLab_RASMANCS
SOFTWARE\Microsoft\Tracing\ZaamLab_RASMANCS
SOFTWARE\Microsoft\Tracing\ZaamLab_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\ZaamLab_RASAPI32
Software\Wow6432Node\Google\Chrome\PreferenceMACs\grirchuvycabgh
Software\Google\Chrome\PreferenceMACs\grirchuvycabgh
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost, value: terana
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost, value: terana
SYSTEM\CurrentControlSet\services\ApplemySU
SYSTEM\ControlSet002\services\ApplemySU
SYSTEM\ControlSet001\services\snare
SYSTEM\CurrentControlSet\services\snare
SYSTEM\CurrentControlSet\services\CSHMDR
SYSTEM\ControlSet002\services\CSHMDR
SYSTEM\ControlSet001\services\CSHMDR
SOFTWARE\Wow6432Node\Microsoft\Tracing\Tripplelux_RASAPI32
SOFTWARE\Microsoft\Tracing\Tripplelux_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\Tripplelux_RASMANCS
SOFTWARE\Microsoft\Tracing\Tripplelux_RASMANCS
Software\Google\Chrome\PreferenceMACs\mizedomdocaentareferly
Software\heheelibom
SOFTWARE\Wow6432Node\wsxy
SOFTWARE\wsxy
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Grerbuseanfale Monitor
SOFTWARE\Wow6432Node\Coehcult
SOFTWARE\Coehcult
SOFTWARE\Wow6432Node\Reoyakesy
SOFTWARE\Reoyakesy
SOFTWARE\Aracerdomarafiy
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Vgockshozety Update
SOSTWARE\Wow6432Node\Ghefyumxkucng
SOSTWARE\Ghefyumxkucng
HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}
WPM
WindowsProtectManger
WindowsMangerProtect
{96ADE61B-8613-4AAD-B22D-2F2E0CE972F6}
{FA9BB55C-9820-4493-9114-2B66FE9AA93F}
{1F5B461D-6BD1-4F21-828F-751A262D058C}
{B75AD60C-A6A1-40E9-98CA-7D7C7B3021AE}
{9BF21B34-A43F-416A-A8D3-EA231B364023}
{951D0E35-BE42-4078-BE4C-68E542A2A5F5}
{14CD3DB6-1BB6-439C-9715-317E15D6B3A7}
{994C5836-82B3-4AC2-BBAC-18CBAB4324FD}
{81DD2CC6-1032-46BD-B276-C00815377F2A}
{4B3BBB1D-B442-4834-BBAC-EA2C5C94FC00}
{CE243463-7723-4A7E-8131-E0854D278A9E}
{8C51856F-6FCA-4F7E-B011-B6EE886E06B9}
{D6593988-0E1F-4469-8C6C-8D6177C45189}
{D4DC11E1-69D6-4054-852B-6B6783363511}
{D0DE0E55-86E5-4063-ABE2-B0EBA61614E1}
{C63DFF15-5E81-42E8-B9B8-8B9FAFFFEDE0}
{AEF2174B-A04E-4F48-9D94-303E088BB9C6}
{AC14E867-D4E4-4766-BE33-D7163CBF73B6}
{9BBB02AA-2F03-4BAD-8013-12A31AABC551}
{9A59D24F-95FC-494A-A83F-9A044542AE5C}
{4D85C02C-3D50-4CE5-B53B-BDE08CC703FE}
{4194745F-D510-4656-985A-32DC67D5BEEF}
{3882CDE4-E12D-45C0-9281-A660FD391F26}
{2F0FD6F0-94DD-4CCA-982F-D399AAA3C1AF}
{2C0B290D-4F04-49D5-8F0B-C84027DDEAAD}
{26BA25CB-BE1B-48FD-919B-952D8DAD8EE2}
{263566A6-F661-44B2-8950-B8F4A551D834}
{1A75AE78-A397-4884-970A-20B6BD33D465}
{0F001336-28FE-41B5-8C6A-6C1AB0754E39}
{A05DF49A-C8F5-4544-B078-A5E9899419E0}
{15B7286A-822A-4DDA-AB3D-D2B72E9D9E4B}
{12C98959-A861-4374-9652-0262B8D2F88D}
{8343610D-81A0-40DE-8DAD-863F1B31AF09}
{0F79AFAA-A465-4727-98A5-DBEC9F98D148}
{802CBEDF-33FE-4835-9BD5-CE322D0A3C42}
{D3FCBA8F-3FCC-4DFF-963E-43A5C3FAA243}
{6E38BBD5-7BA7-4A69-A5B4-D800E502C8FE}
{3D7D8AF8-6705-44F2-BEBD-1B5FEB987326}
{46B8075D-5C81-46DB-906B-FF77D19E25AC}
{686705D8-9D81-4A63-9FF1-0C24FABC93BF}
{E7EE5FBB-E3D2-4F35-9EA6-96C86895759D}
{5A31DD5A-30C8-4DEC-9C41-AD77901D9F82}
{1073E15B-D66A-4FEB-904E-B68BD8E8DC5F}
{F6F90CB6-B50E-4F3C-95C5-BF98B52E65AD}
{BC99F458-B123-4B8C-BC5D-A791CA27696E}
{FE3ACF26-D467-432C-A55E-DA24C9D31B07}
{734814B8-DE5F-4904-A178-0777D777743F}
{BD41788A-329B-486D-BD77-5763DB199D7E}
{19539992-061C-4E8B-9053-07B175303AF4}
{B87478BE-5481-4A88-89E7-06D98AAB45A8}
{D5B0D818-8F09-447F-BEA9-6F571305C7EB}
{77FF926D-26E3-41FB-854C-9B000B1B054E}
{2D7A9DE0-A61B-4555-9E44-8485AE3DB8A8}
{EA124B60-CB4D-46D2-BE17-DC0B75B25051}
{054AE96B-6225-4F87-AC9F-672F8755E9DB}
{AA2198AE-3505-4512-B723-D117381029D1}
{D682D282-B5DD-46B2-B6D0-6CA360961DC4}
{6000ED31-B4F4-4536-A8A1-B10B5BB0518E}
{40D09AFC-379C-4685-9751-4B77E409CF4F}
{25CC0D48-EC3E-4F13-ADED-FBA57AD16871}
{CD2687AB-BA2F-426C-AA61-1E7001AC5D84}
{F7703588-1592-4924-8E4F-109C18F62D25}
{E64E76ED-6454-4DAB-92AB-CAEF20F135DD}
{18BECC8B-F86D-4EAD-8BA7-34B8D98D057C}
{312DAE7A-FF12-4D74-9513-20B74224E514}
{B9980A7C-F0DE-4E2E-8438-8B7511AF8D45}
{85737C81-D46E-469C-9AA4-6AF8E83BD672}
{70DC04B4-15E0-4B5E-BDC7-19060EAE76B6}
{14876A21-EBB2-4FD0-B736-5E888B02D305}
{1E77B4B1-58F9-4EEB-9045-F9ABC4AC49DD}
The following CLSID's were found:
HKEY..\..\{CLSID Path}
{02635D80-A738-11E6-8C1E-64006A5CFC23}
{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
{63D1FFE6-AB7C-11E6-9031-64006A5CFC23}
{84416237-6490-494D-9AD6-4994DD978971}
{C1C7EF78-A5CB-11E6-BBCC-64006A5CFC23}
{C32DE88C-A5AB-11E6-B3D3-64006A5CFC23}
{E733165D-CBCF-4FDA-883E-ADEF965B476C}

Site Disclaimer

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as is:
What is 5 + 9 ?