Multiplug

Multiplug Description

If your anti-virus software is detecting a Multiplug infection, this may mean that adware has been detected on your computer. These types of infections take the form of an extension or toolbar for your Web browser and are designed to generate revenue from advertising and affiliate marketing on the affected computer. The Multiplug infections are not particularly threatening and can be removed in a simpler manner than with other, more severe types of threats. However, despite that the Multiplug infection is categorized as adware, this does not mean that Multiplug is not severely disruptive. Many of the symptoms associated with Multiplug also may appear in cases of a more harmful threat like the Sirefef rootkit.

Multiplug may make the affected Web browser difficult to use and also may be difficult to remove completely because, if not removed entirely, Multiplug may come back to the affected computer. The Multiplug infections may cause the appearance of pop-up windows and error messages and cause alterations to your computer and Web browser preferences. In most cases, Multiplug also may make it difficult to use the affected Web browser because of its constant interruptions.

The Advertisements Exhibited by Multiplug May Lead to Unsafe Websites

Symptoms associated with Multiplug may prevent computer users from using the infected computer effectively. The main purpose of Multiplug and similar infections is to profit at the expense of the computer user, mainly using advertisement revenue and affiliate marketing schemes. Because of this, the main purpose of Multiplug infections is to display advertisements on the infected Web browser or to force computer users to visit websites containing advertisements and affiliate marketing links repeatedly. Multiplug also may insert advertisements and links into online content that would normally not have these types of components. Many of these advertisements may be disruptive, and include video or audio content.

Multiplug may add banners, linked text, and similar advertisements to websites viewed on the affected Web browser. Many of the advertisements associated with Multiplug may be difficult to close, appear repeatedly, or open new Web browser windows or tabs when the computer user closes the advertisements. Some of the symptoms of the Multiplug infections that may be noticed easily include browser redirects to websites associated with Multiplug, the appearance of an unwanted toolbar on the infected Web browser, changes to the compromised Web browser's homepage and default search engine, browser redirects to websites associated with Multiplug, and poor system and Web browser's performance and Internet connection speed. Multiplug may change the affected Web browser's homepage and default search engine to websites associated with Multiplug and, in some cases, also may change the affected Web browser's security settings to make it easier for other unwanted components to be installed.

How Multiplug may Enter a Computer

The main way in which Multiplug is distributed is by bundling this adware with legitimate, free software. Shady marketers may hide Multiplug and the option to opt out of installing these types of components. Browser toolbars associated with Multiplug are very common when downloading free software from download websites with poorly regulated content. You can stay away from these types of tactics by paying attention to the installation process when installing new software on your computer. In many cases, computer users may be opted in automatically to begin the installation of Multiplug when installing other software. The option to drop out may be hidden, needing computer users to select 'custom' or 'advanced' installation. The language informing the computer user on how to opt out of installing Multiplug may be convoluted, using double negatives as well as multiple, confusing confirmation messages. This is all deliberate, ensuring that inexperienced computer users allow Multiplug to enter their computers, believing Multiplug to be a legitimate component.

Aliases: HEUR/QVM10.1.Malware.Gen, Adware.Win32.MultiPlug.BDFn, Generic6.AXCM [AVG], Riskware/MultiPlug [Fortinet], PUA.Multiplug [Ikarus], Win32.Trojan-dropper.Agent.Hquy, Generic Suspicious [Panda], suspected of Heur.Malware-Cryptor.Multiplug, PUP/Win32.MultiPlug [AhnLab-V3], Trojan.Adware.Kazy.D97F0B, ADWARE/MultiPlug.Gen4, AdWare/MultiPlug.hsno, Gen:Variant.Adware.Kazy.622347 (B), MultiPlug-FYT [McAfee-GW-Edition] and TROJ_GEN.R021C0FF915 [TrendMicro].

Technical Information

File System Details

Multiplug creates the following file(s):
# File Name Size MD5 Detection Count
1 %PROGRAMFILES%\ShopperamaIsDaBest\shopperamaisdabest_helper_service.exe 191,696 eafb798e13c296281878e70bcfe41a69 242
2 %USERPROFILE%\Ustawienia lokalne\Dane aplikacji\Cool getWeather\cool_getweather_helper_service.exe 191,692 17f601c301cfcf559f496bf268533fc1 205
3 %ALLUSERSPROFILE%\yzmT.exe\yzmT.exe 301,056 01013ed465ace5a0654af5eae4182427 129
4 %ALLUSERSPROFILE%\TextEnhance_26.0.1773.401\TextEnhance_26.0.1773.401.dll 2,726,912 43eea0c9b47d493fa5cbb7f823f6b14f 19
5 %ALLUSERSPROFILE%\flKgbm\pIUQIBtrSr.exe 2,730,472 9442cd76d133358d1d75189fd654d52e 9
6 %ALLUSERSPROFILE%\{6b557f3a-3b86-64ba-6b55-57f3a3b8fce8}\setup_product_461.exe 2,563,072 9338a0241e53f020fdb2dbc1f3384771 6
7 %PROGRAMFILES(x86)%\LightEngine\LightEngine.dll 2,820,608 9587cc7cc884e0520acc087765c6f669 2
8 %PROGRAMFILES(x86)%\SectionDouble\SectionDouble.dll 2,311,168 d3f78a9c77022686e8587f152761bb8d 1
9 %PROGRAMFILES%\PragmaGeneration\PragmaGeneration.dll 1,591,808 567dacf8e9a8e4004e074487ad66a775 1
10 %PROGRAMFILES(x86)%\PragmaMaker\PragmaMaker.dll 1,593,344 3342fa5886b24bee806fb1ba466ebd48 1
11 %PROGRAMFILES(x86)%\PragmaModulator\PragmaModulator.dll 1,639,424 62392fe537be5fb8932569d61cab66bc 1
12 %PROGRAMFILES%\PragmaMonitor\PragmaMonitor.dll 1,646,592 e845a02ade4d0e6ce26303989c0c366c 1
13 %ALLUSERSPROFILE%\{4b22572e-5d6b-90ae-4b22-2572e5d65cb9}\spyhunter 4.17.6.4336 full version with patch.exe 2,047,488 af8685a1052b3013679584c6246284b7 1
14 %ALLUSERSPROFILE%\{83665d8d-949c-051f-8366-65d8d9497636}\Troj31.exe 384,512 6b940263fda0d67f604a7784c9db2390 1
15 %USERPROFILE%\My Documents\TextEnhance.exe 8,399,568 c05c9608289ac4bdaea46e31308d3531 1
16 %ALLUSERSPROFILE%\{fdf14b40-ef71-f3da-fdf1-14b40ef72d03}\530a2f59766c6e10e17a590330eb466a6edbbfe27acb608f65872e4efba42a65.exe 197,632 c32708db1ad2317e4595dd974b143d56 1
17 %PROGRAMFILES%\Perplexed Examination\Perplexed Examination.exe 8,016,472 d7411b426fbed97813cff3775e932df4 1
18 %PROGRAMFILES%\wincheck\wincheck.dll 3,131,392 43a263e7094f03cf901677c928a871f0 1
19 %PROGRAMFILES(x86)%\sayescoupon\sayescoupon.dll 3,124,736 4c1828421115566c175b1068ab5bfee5 1
20 %ALLUSERSPROFILE%\{637939e6-2f02-489f-6379-939e62f0e798}\sevensetup.exe 210,432 e21184b2c8810524d277c1e76d290c69 1
21 %ALLUSERSPROFILE%\{6b6814d7-c7b9-cfeb-6b68-814d7c7b535f}\spyhunter.4.19.13.4482.rarspyhunter.4.19.13.4482.exe 261,632 17569888b2a2b83731aad52cc0f55268 1
22 %ALLUSERSPROFILE%\{5604558a-240d-a3ee-5604-4558a2405628}\c441161db158ad39ace471a3b983c916a075d946d5f52329046d8bf9f77b1575.exe 352,256 e99ddf50f193feb7f6a22017f2886934 1
23 %ALLUSERSPROFILE%\Web Light\WebLight_x64.dll 4,332,544 5ce8eb47df6a284281572ff9ef95012e 1
24 %ALLUSERSPROFILE%\Web Light\weblight.dll 4,391,424 b5c305c3b2ff2e35d4a270fad0675649 1
25 %ALLUSERSPROFILE%\TextEnhance_6.2.2999.522\TextEnhance_6.2.2999.522.dll 2,930,688 3b2697d63c404ce3eec49de4c4741c0f 1
26 Flava Clipper.exe 522,752 1ce9fe173a0c0d14a670488daee98fcf 0
27 file.exe 497,664 e20d9121513d22e39a64034dcf41d1cd 0
More files

Registry Details

Multiplug creates the following registry entry or registry entries:
Directory
%ALLUSERSPROFILE%\5e6fb5de08469020
%ALLUSERSPROFILE%\Accelewin
%ALLUSERSPROFILE%\Application Data\Accelewin
%ALLUSERSPROFILE%\Application Data\Browser Enhancer
%ALLUSERSPROFILE%\Application Data\Browser Stabilizer
%ALLUSERSPROFILE%\Application Data\Content Accelerator
%ALLUSERSPROFILE%\Application Data\FastSys
%ALLUSERSPROFILE%\Application Data\Intelewin filter
%ALLUSERSPROFILE%\Application Data\InteliWeb
%ALLUSERSPROFILE%\Application Data\Interenet Optimizer
%ALLUSERSPROFILE%\Application Data\Performance Optimizer
%ALLUSERSPROFILE%\Application Data\Speed Streamer
%ALLUSERSPROFILE%\Application Data\System Booster
%ALLUSERSPROFILE%\Application Data\TurboNet
%ALLUSERSPROFILE%\Application Data\WebGeniuos
%ALLUSERSPROFILE%\Application Data\WebPlat
%ALLUSERSPROFILE%\Application Data\Win sys filter
%ALLUSERSPROFILE%\Application Data\WinSpeed
%ALLUSERSPROFILE%\Application Data\WorldWideWebCoupon
%ALLUSERSPROFILE%\Browser Enhancer
%ALLUSERSPROFILE%\Browser Stabilizer
%ALLUSERSPROFILE%\Codec-C
%ALLUSERSPROFILE%\CodecC
%ALLUSERSPROFILE%\Content Accelerator
%ALLUSERSPROFILE%\Coolyou
%ALLUSERSPROFILE%\FastSys
%ALLUSERSPROFILE%\Intelewin filter
%ALLUSERSPROFILE%\InteliWeb
%ALLUSERSPROFILE%\Interenet Optimizer
%ALLUSERSPROFILE%\Network Acceleration
%ALLUSERSPROFILE%\Performance Optimizer
%ALLUSERSPROFILE%\Speed Streamer
%ALLUSERSPROFILE%\Surf Protect
%ALLUSERSPROFILE%\System Booster
%ALLUSERSPROFILE%\TurboNet
%ALLUSERSPROFILE%\Web Light
%ALLUSERSPROFILE%\WebGeniuos
%ALLUSERSPROFILE%\WebPlat
%ALLUSERSPROFILE%\WebTouch
%ALLUSERSPROFILE%\Win sys filter
%ALLUSERSPROFILE%\WinSpeed
%ALLUSERSPROFILE%\WorldWideWebCoupon
%PROGRAMFILES%\ Mail Checker
%PROGRAMFILES%\ Similar Pages
%PROGRAMFILES%\ Translate
%PROGRAMFILES%\BocaEdit
%PROGRAMFILES%\BocaFunc
%PROGRAMFILES%\ChromeReload
%PROGRAMFILES%\Clip to OneNote
%PROGRAMFILES%\coPuunk
%PROGRAMFILES%\CutterMaker
%ProgramFiles%\DeltaFix
%PROGRAMFILES%\DiscountCouponPro
%PROGRAMFILES%\Godzilla Shopper
%PROGRAMFILES%\IncludeMaker
%PROGRAMFILES%\IncludeRunner
%PROGRAMFILES%\IndepthEdit
%PROGRAMFILES%\IndepthRunner
%PROGRAMFILES%\myselfcoupon
%PROGRAMFILES%\PragmaEngine
%PROGRAMFILES%\reactorrise
%PROGRAMFILES%\SoftwareHelp
%PROGRAMFILES%\TerminusSys
%PROGRAMFILES%\toolextender
%PROGRAMFILES%\TotalComicBooks
%PROGRAMFILES%\TrimModule
%PROGRAMFILES%\UpgradeLeader
%PROGRAMFILES%\Weather Aware
%PROGRAMFILES(X86)%\ Mail Checker
%PROGRAMFILES(x86)%\ Similar Pages
%PROGRAMFILES(X86)%\ Translate
%PROGRAMFILES(x86)%\BocaEdit
%PROGRAMFILES(x86)%\BocaFunc
%PROGRAMFILES(x86)%\ChromeReload
%PROGRAMFILES(x86)%\Clip to OneNote
%PROGRAMFILES(x86)%\coPuunk
%PROGRAMFILES(x86)%\CutterMaker
%ProgramFiles(x86)%\DeltaFix
%PROGRAMFILES(x86)%\DiscountCouponPro
%PROGRAMFILES(x86)%\Godzilla Shopper
%PROGRAMFILES(x86)%\IncludeMaker
%PROGRAMFILES(x86)%\IncludeRunner
%PROGRAMFILES(x86)%\IndepthEdit
%PROGRAMFILES(x86)%\IndepthRunner
%PROGRAMFILES(x86)%\myselfcoupon
%PROGRAMFILES(x86)%\PragmaEngine
%PROGRAMFILES(x86)%\reactorrise
%PROGRAMFILES(x86)%\SoftwareHelp
%PROGRAMFILES(x86)%\TerminusSys
%PROGRAMFILES(x86)%\toolextender
%PROGRAMFILES(X86)%\TotalComicBooks
%PROGRAMFILES(x86)%\TrimModule
%PROGRAMFILES(x86)%\UpgradeLeader
%PROGRAMFILES(x86)%\Weather Aware
Registry key
Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
SOFTWARE\Classes\..9
Software\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\BestSleep.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\BestSleep.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Bidaily Synchronize Task.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Bidaily Synchronize Task.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Bidaily Synchronize Task[3c32].job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Bidaily Synchronize Task[3c32].job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Bidaily Synchronize Task[74c7].job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Bidaily Synchronize Task[74c7].job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Bidaily Synchronize Task[pr].job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Bidaily Synchronize Task[pr].job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task[3c32]
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task[74c7]
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Bidaily Synchronize Task[pr]
SOFTWARE\Wow6432Node\{12A61307-94CD-4F8E-94BC-918E511FAA81}
SOFTWARE\Wow6432Node\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
SOFTWARE\Wow6432Node\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
SOFTWARE\Wow6432Node\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Software\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
SYSTEM\ControlSet001\services\1998d97c
SYSTEM\ControlSet001\Services\24c54e38
SYSTEM\ControlSet001\services\6135ae48
SYSTEM\ControlSet001\services\813b67ce
SYSTEM\ControlSet001\Services\863788fa
SYSTEM\ControlSet001\services\a89d7674
SYSTEM\ControlSet001\services\a952796e
SYSTEM\ControlSet001\services\abc71024
SYSTEM\ControlSet001\services\cf05acd1
SYSTEM\ControlSet001\Services\d45d88d8
SYSTEM\ControlSet001\Services\d6b52028
SYSTEM\ControlSet001\services\e3f7f5ff
SYSTEM\ControlSet001\services\fc67e7a0
SYSTEM\ControlSet001\services\fd3b02ee
SYSTEM\ControlSet002\services\1998d97c
SYSTEM\ControlSet002\Services\24c54e38
SYSTEM\ControlSet002\services\6135ae48
SYSTEM\ControlSet002\services\a952796e
SYSTEM\ControlSet002\services\abc71024
SYSTEM\ControlSet002\services\cf05acd1
SYSTEM\ControlSet002\Services\d6b52028
SYSTEM\ControlSet002\services\e3f7f5ff
SYSTEM\ControlSet002\services\fc67e7a0
SYSTEM\ControlSet002\services\fd3b02ee
SYSTEM\CurrentControlSet\services\1998d97c
SYSTEM\CurrentControlSet\Services\24c54e38
SYSTEM\CurrentControlSet\services\6135ae48
SYSTEM\CurrentControlSet\services\813b67ce
SYSTEM\CurrentControlSet\Services\863788fa
SYSTEM\CurrentControlSet\services\a89d7674
SYSTEM\CurrentControlSet\Services\a952796e
SYSTEM\CurrentControlSet\services\abc71024
SYSTEM\CurrentControlSet\services\cf05acd1
SYSTEM\CurrentControlSet\Services\d45d88d8
SYSTEM\CurrentControlSet\Services\d6b52028
SYSTEM\CurrentControlSet\services\e3f7f5ff
SYSTEM\CurrentControlSet\services\fc67e7a0
SYSTEM\CurrentControlSet\services\fd3b02ee
Regexp file mask
%APPDATA%\appdataFr[NUMBERS].bin
%PROGRAMFILES%\AppendGeneration\AppendGeneration.dll
%PROGRAMFILES%\AppendInit\AppendInit.dll
%PROGRAMFILES%\AppendMonitor\AppendMonitor.dll
%PROGRAMFILES%\BorderlineMaker\BorderlineMaker.dll
%PROGRAMFILES%\brainwash\brainwash.dll
%PROGRAMFILES%\CutterFoobar\CutterFoobar.dll
%PROGRAMFILES%\decodit\decodit.dll
%PROGRAMFILES%\goopad\goopad.dll
%PROGRAMFILES%\IncludeInstance\IncludeInstance.dll
%PROGRAMFILES%\IncludeMonitor\IncludeMonitor.dll
%PROGRAMFILES%\IncrementEdit\IncrementEdit.dll
%PROGRAMFILES%\IncrementModule\IncrementModule.dll
%PROGRAMFILES%\IncrementMonitor\IncrementMonitor.dll
%PROGRAMFILES%\IndepthFunc\IndepthFunc.dll
%PROGRAMFILES%\LinkFunc\LinkFunc.dll
%PROGRAMFILES%\PathFoobar\PathFoobar.dll
%PROGRAMFILES%\PragmaEdit\PragmaEdit.dll
%PROGRAMFILES%\ProcessFoobar\ProcessFoobar.dll
%PROGRAMFILES%\ProcessMaker\ProcessMaker.dll
%PROGRAMFILES%\ReactorKeeper\ReactorKeeper.dll
%PROGRAMFILES%\ReactorSubs\ReactorSubs.dll
%PROGRAMFILES%\RelayDouble\RelayDouble.dll
%PROGRAMFILES%\RelaySoft\RelaySoft.dll
%PROGRAMFILES%\RelaySys\RelaySys.dll
%PROGRAMFILES%\sayescoupon\sayescoupon.dll
%PROGRAMFILES%\SegmentProlonger\SegmentProlonger.dll
%PROGRAMFILES%\SegmentSystem\SegmentSystem.dll
%PROGRAMFILES%\SoftwarePlus\SoftwarePlus.dll
%PROGRAMFILES%\StatFoobar\StatFoobar.dll
%PROGRAMFILES%\SystemConserve\SystemConserve.dll
%PROGRAMFILES%\SystemEnterprise\SystemEnterprise.dll
%PROGRAMFILES%\SystemHelp\SystemHelp.dll
%PROGRAMFILES%\SystemRaise\SystemRaise.dll
%PROGRAMFILES%\SystemUphold\SystemUphold.dll
%PROGRAMFILES%\TerminusDefender\TerminusDefender.dll
%PROGRAMFILES%\TerminusExtender\TerminusExtender.dll
%PROGRAMFILES%\TerminusMaker\TerminusMaker.dll
%PROGRAMFILES%\ToolMaker\ToolMaker.dll
%PROGRAMFILES%\TrimAppend\TrimAppend.dll
%PROGRAMFILES%\TrimEdit\TrimEdit.dll
%PROGRAMFILES%\turbostrength\turbostrength.dll
%PROGRAMFILES(x86)%\AppendEngine\AppendEngine.dll
%PROGRAMFILES(x86)%\AppendFoobar\AppendFoobar.dll
%PROGRAMFILES(x86)%\AppendInit\AppendInit.dll
%PROGRAMFILES(x86)%\AppendModule\AppendModule.dll
%PROGRAMFILES(x86)%\AppendRunner\AppendRunner.dll
%PROGRAMFILES(x86)%\BorderlineEngine\BorderlineEngine.dll
%PROGRAMFILES(x86)%\BorderlineInit\BorderlineInit.dll
%PROGRAMFILES(x86)%\BorderlineMonitor\BorderlineMonitor.dll
%PROGRAMFILES(x86)%\couponight\couponight.dll
%PROGRAMFILES(x86)%\CutterFoobar\CutterFoobar.dll
%PROGRAMFILES(x86)%\CutterProc\CutterProc.dll
%PROGRAMFILES(x86)%\decodit\decodit.dll
%PROGRAMFILES(x86)%\goopad\goopad.dll
%PROGRAMFILES(x86)%\IncludeInstance\IncludeInstance.dll
%PROGRAMFILES(x86)%\IncrementEdit\IncrementEdit.dll
%PROGRAMFILES(x86)%\IncrementFunc\IncrementFunc.dll
%PROGRAMFILES(x86)%\IncrementProc\IncrementProc.dll
%PROGRAMFILES(x86)%\IndepthEngine\IndepthEngine.dll
%PROGRAMFILES(x86)%\IndepthMonitor\IndepthMonitor.dll
%PROGRAMFILES(x86)%\IndepthProc\IndepthProc.dll
%PROGRAMFILES(x86)%\LinkFunc\LinkFunc.dll
%PROGRAMFILES(x86)%\LinkGeneration\LinkGeneration.dll
%PROGRAMFILES(x86)%\PathGeneration\PathGeneration.dll
%PROGRAMFILES(x86)%\PragmaEdit\PragmaEdit.dll
%PROGRAMFILES(x86)%\PragmaGeneration\PragmaGeneration.dll
%PROGRAMFILES(x86)%\PragmaMaker\PragmaMaker.dll
%PROGRAMFILES(x86)%\PragmaModulator\PragmaModulator.dll
%PROGRAMFILES(x86)%\PragmaSystem\PragmaSystem.dll
%PROGRAMFILES(x86)%\ProcessMaker\ProcessMaker.dll
%PROGRAMFILES(x86)%\ProcessRunner\ProcessRunner.dll
%PROGRAMFILES(x86)%\ReactorKeeper\ReactorKeeper.dll
%PROGRAMFILES(x86)%\RelayDefender\RelayDefender.dll
%PROGRAMFILES(x86)%\RelayDouble\RelayDouble.dll
%PROGRAMFILES(x86)%\RelaySoft\RelaySoft.dll
%PROGRAMFILES(x86)%\RelaySys\RelaySys.dll
%PROGRAMFILES(X86)%\sayescoupon\sayescoupon.dll
%PROGRAMFILES(x86)%\SegmentProlonger\SegmentProlonger.dll
%PROGRAMFILES(x86)%\SoftwarePlus\SoftwarePlus.dll
%PROGRAMFILES(x86)%\StatFoobar\StatFoobar.dll
%PROGRAMFILES(x86)%\StatInit\StatInit.dll
%PROGRAMFILES(x86)%\SystemChronicles\SystemChronicles.dll
%PROGRAMFILES(x86)%\SystemConserve\SystemConserve.dll
%PROGRAMFILES(x86)%\SystemContinue\SystemContinue.dll
%PROGRAMFILES(x86)%\SystemEnterprise\SystemEnterprise.dll
%PROGRAMFILES(x86)%\SystemHelp\SystemHelp.dll
%PROGRAMFILES(x86)%\SystemPlus\SystemPlus.dll
%PROGRAMFILES(x86)%\systempreserve\systempreserve.dll
%PROGRAMFILES(x86)%\SystemRaise\SystemRaise.dll
%PROGRAMFILES(x86)%\TampaFoobar\TampaFoobar.dll
%PROGRAMFILES(x86)%\TampaModule\TampaModule.dll
%PROGRAMFILES(x86)%\TampaMonitor\TampaMonitor.dll
%PROGRAMFILES(x86)%\TampaRunner\TampaRunner.dll
%PROGRAMFILES(x86)%\TerminusDefender\TerminusDefender.dll
%PROGRAMFILES(x86)%\TerminusKeeper\TerminusKeeper.dll
%PROGRAMFILES(x86)%\TerminusMaker\TerminusMaker.dll
%PROGRAMFILES(x86)%\TrimFunc\TrimFunc.dll
%PROGRAMFILES(x86)%\TrimInit\TrimInit.dll
%PROGRAMFILES(x86)%\TrimMaker\TrimMaker.dll
Uninstaller
S-46480778
{11F6D5AB-263F-388E-74DE-E3DECD390E3F}
{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{813b67ce}
{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{fc67e7a0}
{355FE5A0-F76C-0FCB-3575-FAD0CBA4A5F3}
{3F7D597C-7512-F73C-B0F3-5D711BC91948}
{476D78C4-1DB0-2D88-7FCC-AA6559F59A8D}
{4820778D-AB0D-6D18-C316-52A6A0E1D507}
{5F189DF5-2D05-472B-9091-84D9848AE48B}{1a34a8e0}
{5F189DF5-2D05-472B-9091-84D9848AE48B}{699fd52f}
{5F189DF5-2D05-472B-9091-84D9848AE48B}{dfc86759}
{5F189DF5-2D05-472B-9091-84D9848AE48B}{e81a9dc1}
{5F189DF5-2D05-472B-9091-84D9848AE48B}{f7dc94c1}
{65886F9B-214B-530F-E4EA-7565AFF6DE8D}
{681002C6-5019-81A2-7871-A43754F71E56}
{6C998B44-82D8-CC7E-D847-4CD73036412A}
{6F10CA8F-97E3-48FB-9003-3EE8E9050577}
{75F9BF4A-AF67-A478-A37B-31D73186D3F3}
{7F90CB46-EB38-83F9-7DB4-CB89897D5836}
{842C4394-47F7-60DE-480B-C09116B63559}
{88E96402-3BBD-02D9-0A36-6FB806AEE04E}
{924C3DC2-8E4E-432E-F973-9A2174A39774}
{A695893E-A5C7-2E5C-6953-52B0E61E4C1A}
{AD11DADE-C597-45D9-D8C5-1D2EB0B89613}
{B0EC0808-6922-8705-C255-F9C79C315BD5}
{B945F928-45A2-231E-495F-38C40CA198E9}
{C1C6816E-CBB3-A748-85F9-A8B47B68985B}
{D8A9D3D9-F414-952D-AC93-E5F96D47B5BD}
{E32743D3-5789-6E4F-3998-06FB87C9214B}
{E96338DC-1468-4918-8EC2-8454BFFC5025}
{F04D4328-4631-1CBE-1907-201B33FAF2E8}
{F364255F-18D3-2E0A-6D4D-A0C3FF4A43B1}
{F679D2F0-CE91-93C8-BD2D-062DF04DA0C1}
{F6EF44E0-CA47-4F41-8C06-431C005AAEFE}
{F7FFE175-E3D6-2E86-0226-1D3AE4905E40}
CLSID
{0F19EF48-CB8C-416A-B84C-C33B02970632}
{138E44EF-8988-4DC7-8F48-FBC4FCEF83D1}
{157B1AA6-3E5C-404A-9118-C1D91F537040}
{382F6195-1B46-40D5-B9FD-0493263E6132}
{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
{3C94CD82-91C5-4DA7-AC36-BC96B16DEB26}
{41F978F3-431A-4464-A789-5C0692D562FB}
{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
{5F189DF5-2D05-472B-9091-84D9848AE48B}
{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}
{9129BF03-EE04-4C16-B8AA-5DA6ADE6AB2B}
{9B41579A-1996-42F9-8F84-7B7786818CEF}
{9D4DC1C6-EFD1-44B1-91F9-6C7D4FC13CBD}
{ADA38E4E-F20A-4399-BE91-E260AC341C69}
{BB1C0445-8E37-4D66-B4E4-947E53F654A8}
{BB50CC62-09E1-4DD9-912C-F1DA4D6D71D8}
{C3510196-382C-41D1-8E63-6E84DB3709C9}
{DFF50D27-9859-4F50-9BE1-A4CBFA102B9D}
{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}
{E2343056-CC08-46AC-B898-BFC7ACF4E755}
{E481A870-86C7-44E1-97DF-E759FC147CBE}
{E55496A1-3090-44B0-96BF-518EA4B6828B}
{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
{EB559340-3A8F-4456-B24D-160098054EF0}
{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}
{FE332809-93C1-48DF-929F-AEC0BC4BFCFE}

Related Posts

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.