Click on screenshot to zoom
Danger level 7
Type: Trojans
Common infection symptoms:
  • Connects to the internet without permission
  • Installs itself without permissions

slingshot malware

Slingshot malware happens to be an extremely malicious Trojan, which you must avoid at all costs. Doing so is crucial because this devious application is designed to act in an intrusive manner. Its developers usually use it to steal sensitive information from the affected computers. Also, this program could prove to be the primary reason other suspicious applications might enter your operating system without a lot of troubles. As you can imagine, having this Trojan up and running on your personal computer could lead to devastating outcomes, to put it lightly. If you want to find out more about its inner workings, be sure to read the rest of this article. Our researchers also present a few virtual security recommendations, which you must take to improve your virtual security. Besides all of that, we include a detailed removal guide, which you should use to delete slingshot malware in just a few simple steps.

It is important to note that it has been noticed that slingshot malware has affected more than 100 computers before being discovered. Most of these attacks were carried out in African and Middle Eastern countries. While that happens to be the case, it is crucial to understand that there are no guarantees that it will not spread elsewhere. Once this Trojan gains successful access to your operating system, it immediately starts doing its dirty work. Unfortunately, the majority of users are unable to identify and remove this program before it starts acting. That is so because it functions in a completely silent manner. First, it replaces your system's files with its own. The devious .dll file then downloads all the components of this malicious application and runs them. It is critical to note this Trojan consists of five different modules, and each of them has a distinct role. It has been identified that a module known as GollumApp has keylogging functionality; it can track your network information and steal passwords stored in your browser. The one entitled SsCB makes numerous screenshots, while ffproxy is designed to collect Firefox proxy settings and other configuration details. The other two modules known as Sfc2 and NeedleWatch are primarily used to inject files into your operating system and to disable Windows' files protection. On top of all that, it has been found out that this Trojan also has a downloader, which could be used to infect your operating system with other dangerous applications. To remove slingshot malware once and for all be sure to follow the instructions that you can find below.

It took some time before malware experts discovered how slingshot malware gains access to the operating system. During the extensive analysis, it has been discovered that malware developers got access to routers made by MikroTik and injected it with a malicious code, which initiated a download of a devious .dll file. Because of such distribution method, all the computers on the network could be infected this the Trojan in question. To keep your operating system free of this malware and other similar applications you need to take precautionary steps to improve your overall virtual security. We highly advise you to check if the network that you wish to connect to is safe and secure. Furthermore, you should know that cyber crooks also use spam email campaigns for distribution purposes. Therefore, we recommend refraining from all emails and email attachments that come your way from unknown third-parties. Also, remember to educate yourself about every application before downloading and installing it on your PC because malware developers are known to fool users by using hoax advertising tactics. Finally, and most importantly, every security-conscious user must have a professional antimalware tool active on their PC. Such a tool is the most important part of your virtual security because it is designed to detect and delete any virtual security threat automatically.

To remove slingshot malware, be sure to follow the instructions below. It is essential to execute this removal guide with care because a single mistake could have undesirable outcomes. Without even knowing you might leave data of this Trojan, which could be used to restore it silently. In other situations, a missed step could mean that this malicious program could continue working. Furthermore, it is important to note that manual removal is a complex task, which should be executed by advanced computer users. Malware researchers at our internal labs highly advise you to use a reliable antimalware tool for removal purposes because it is designed to delete slingshot malware and everything associated with it automatically.

How to remove slingshot malware from your PC

  1. Open your File Explorer.
  2. Go to C:\Windows\System32.
  3. Select a file called scesrv.dll and then replace it with the original one.
  4. Go to C:\Windows\SysWow64.
  5. Select a file called scesrv.dll and then replace it with the original one.
  6. Close your File Explorer.
  7. Restart your PC.
Download Spyware Removal Tool to Remove* slingshot malware
  • Quick & tested solution for slingshot malware removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove slingshot malware

Files associated with slingshot malware infection:

%ProgramFiles%\thc?????????
hesudobu.dll
nupotuku.dll
iyupodovujepope.dll
svcchosst.exe
kdpini.dll
penipure.dll
%SystemRoot%\System32\rhc?????????
vosevodi.dll
%ProgramFiles%\643f??????????
%UserProfile%\thc?????????
KBDURsr.dll
xydzyh.exe
ope2314.exe
%UserProfile%\Application Data\643f??????????
oyuwopoze.dll
kory.exe
vabofoka.dll
nl3.exe
dx8vb32.dll
icocalolacihir.dll
%SystemRoot%\System32\whc?????????
topapope.dll
ofriasc.dll
ClipHelp3xx.dll
omshtup.dll
delidubu.dll
Ffodoa.exe
%SystemRoot%\System32
sumonibe.dll
zyex.exe
bdsl2.dll
nohisoye.dll
irulusasiyuwam.dll
kalerazo.dll
asvdxl.dll
%UserProfile%\Application Data\whc?????????
zs880000[1].exe
srenum.sys
dibawumi.dll
yopalimi.dll
uyefesujoxumu.dll
zelovumi.dll
ixelinet.dll
%ProgramFiles%\phc?????????
sekisahi.dll
mulirowo.dll
odbn0.exe
bopufeto.dll
sdasda.exe
cmdial3.dll
roam five.exe
sujibiwi.dll
pokumala.dll
pcpriv.exe
uyuhapuhid.dll
hepigalo.exe
doriyubi.dll
%UserProfile%\blphc?????????
obaluqizevax.dll
Warn Support.exe
poqii.exe
futewege.dll
zemupalu.dll
bisevona.dll
dot3cfg32.dll
%ProgramFiles%\blphc?????????
vubabuku.dll
kulo.exe
%UserProfile%\Application Data\blphc?????????
irxoe.exe
debodoro.dll
bawawaza.dll
%UserProfile%\bpph??????????
dmutil32.dll
balomane.dll
onifr.exe
wisysvi.dll
mafuyiha.dll
mokehohi.dll
ajuquqoqepoqu.dll
winlo.exe
uzewerilupavid.dll
cajiw.exe
yovalono.dll
yikuhawa.dll
beipq.exe
nahatona.dll
idojapimogudoray.dll
sihosido.dll
kafunepi.dll
ree2.exe
uheludeje.dll
bdsyslink.dll
logomafe.dll
zipavagi.dll
morugawe.dll
papororo.dll
alivevukov.dll
zorihali.dll
caese.exe
ijusuyanami.dll
AdobeSoftVaallupjhn.exe
lebenesa.dll
juhalobo.dll
pujosove.dll
bupuyafo.dll
asade.exe
uqogumamumuse.dll
pascmgp.exe
pivumedo.dll
junefare.dll
miduyevu.dll
ovamudutibofe.dll
zezowawi.dll
%UserProfile%\rhc?????????
xoipk.exe
%UserProfile%\lphc?????????
rigiwoti.dll
akihovojamaz.dll
Lxh.exe
wehebopa.dll
vupesasu.dll
norozuse.dll
ijucahalevet.dll
pjdeya.exe
mukejowe.dll
uclyv.exe
%UserProfile%\Application Data\rhc?????????
%UserProfile%\Application Data\phc?????????
yowujeje.dll
lewiyidi.dll
kurtapt24@yahoo.com
asycfil.dll
%ProgramFiles%\bpph??????????
relereni.dll
penis.exe
livukafa.dll
%TEMP%
%SystemRoot%\System32\bpph??????????
tikatabi.dll
iqugumamu.dll
1361163109.exe
nl2.exe
mcfg.exe
iksuy.exe
zarebeba.dll
%UserProfile%
nutowuko.dll
qycu.exe
reqi.exe
%ProgramFiles%\lphc?????????
akuzivazoveraxif.dll
togojaze.dll
SerialsWorld.exe
AcroIEHelpe022.dll
tepepife.dll
hoyuvuki.dll
fezahoyu.dll
nl5.exe
PowerJa.ask
%UserProfile%\Application Data\bpph??????????
fwtrtuqtssd.exe
jahasike.dll
nl4.exe
kifupiza.dll
eruzurow.dll
palowaru.dll
fehamito.dll
dxva2C.dll
%SystemRoot%\System32\thc?????????
jelayube.dll
uqiwaceh.dll
ibitolet.dll
eloheseweriquyi.dll
xipr.exe
baka6.exe
%SystemRoot%\System32\phc?????????
udihozazohec.dll
yamanewa.dll
fejolave.dll
idumowapupiy.dll
oderobifamaves.dll
mejiyolo.dll
csrcs.exe
ptidle.exe
ufdsvc.exe
evizavohiyesupa.dll
hehoyoze.dll
sonuleme.dll
rdolib.dll
bujiwofi.dll
unapatax.dll
verabija.dll
itufijorece.dll
hovebipu.dll
bovekafu.dll
bdaplgini.dll
lopibeki.dll
207163515.exe
vopereso.dll
tijawani.dll
%SystemRoot%\System32\blphc?????????
oqifubeqixi.dll
rexsvc32.exe
%UserProfile%\whc?????????
sogidona.dll
flsysio.exe
nupanogo.dll
jimofiji.dll
juriyuyi.dll
kekasika.dll
%UserProfile%\Application Data\lphc?????????
kedisuzo.dll
SystemAutorun.exe
wirepots.exe
sysrc32.exe
RqAds.exe
%UserProfile%\Application Data\pphc?????????
ree1.exe
nageduge.dll
nevoputo.dll
luyehije.dll
idolowun.dll
refobaju.dll
dizubure.dll
emihotepopeg.dll
%SystemRoot%\System32\lphc?????????
UnLoad.exe
uvojigulukacega.dll
fozusayo.dll
%UserProfile%\pphc?????????
%ProgramFiles%\whc?????????
fechme.exe
%SystemRoot%\System32\643f??????????
MySelf.exe
ehczrw312.exe
ufimixefenoy.dll
vcnews.exe
muyinepa.dll
nl6.exe
realsvc.exe
nsx23.dll
aim remote.exe
%ProgramFiles%\rhc?????????
DisplaySwitch.exe
dodohovo.dll
dijanumo.dll
winmyy32.dll
uvumaxeqa.dll
kozeyizu.dll
wahayaga.dll
%UserProfile%\phc?????????
potibubi.dll
mivi.exe
etomemap.dll
%UserProfile%\Application Data
barijatu.dll
fenofaki.dll
yosineku.dll
digiwet.dll
kusers.dll
mivalivo.dll
%UserProfile%\Application Data\thc?????????
hukubuhu.dll
evejubet.dll
comparevers.exe
sgpron.dll
kbdnet.dll
oviyukebicitaq.dll
vybi.exe
mutelupo.dll
uqojanecatevih.dll
stuvwxy.exe
hnwqrys.exe
photo_id.exe
nuviyapi.dll
VCL.dll
aboheraj.dll
wujiwibe.dll
yatodimi.dll
zofowoda.dll
kavumefe.dll
afitegef.dll
%ProgramFiles%\pphc?????????
kylo.exe
%UserProfile%\643f??????????
pehuraba.dll
uhoyureg.dll
icaqx.exe
robejaku.dll
dwm.exe
lepopoka.dll
nobajanu.dll
%SystemRoot%\System32\pphc?????????
bufezeza.dll
atl7.dll
fahokipa.dll
ugavisidu.dll
%ProgramFiles%

slingshot malware DLL's to remove:

uyefesujoxumu.dll
udihozazohec.dll
doriyubi.dll
digiwet.dll
dot3cfg32.dll
bisevona.dll
AcroIEHelpe022.dll
sumonibe.dll
asycfil.dll
itufijorece.dll
yosineku.dll
nevoputo.dll
unapatax.dll
morugawe.dll
sekisahi.dll
nuviyapi.dll
luyehije.dll
kifupiza.dll
nutowuko.dll
akihovojamaz.dll
nsx23.dll
uqojanecatevih.dll
yovalono.dll
evejubet.dll
lopibeki.dll
yowujeje.dll
balomane.dll
fozusayo.dll
nobajanu.dll
uqiwaceh.dll
ugavisidu.dll
pehuraba.dll
uheludeje.dll
mafuyiha.dll
yopalimi.dll
ijusuyanami.dll
kafunepi.dll
ajuquqoqepoqu.dll
wisysvi.dll
topapope.dll
sogidona.dll
togojaze.dll
pivumedo.dll
eloheseweriquyi.dll
sgpron.dll
kalerazo.dll
barijatu.dll
hehoyoze.dll
hovebipu.dll
juriyuyi.dll
aboheraj.dll
zarebeba.dll
dodohovo.dll
KBDURsr.dll
delidubu.dll
nupanogo.dll
hoyuvuki.dll
livukafa.dll
yatodimi.dll
bufezeza.dll
nupotuku.dll
asvdxl.dll
atl7.dll
obaluqizevax.dll
kusers.dll
oqifubeqixi.dll
dizubure.dll
ClipHelp3xx.dll
yamanewa.dll
futewege.dll
bdsyslink.dll
jimofiji.dll
penipure.dll
junefare.dll
oviyukebicitaq.dll
vubabuku.dll
mejiyolo.dll
fahokipa.dll
sujibiwi.dll
fenofaki.dll
kedisuzo.dll
uvojigulukacega.dll
ufimixefenoy.dll
lewiyidi.dll
vupesasu.dll
kdpini.dll
pokumala.dll
zemupalu.dll
uqogumamumuse.dll
juhalobo.dll
mukejowe.dll
idojapimogudoray.dll
jahasike.dll
uvumaxeqa.dll
nohisoye.dll
eruzurow.dll
iyupodovujepope.dll
icocalolacihir.dll
vopereso.dll
zelovumi.dll
ofriasc.dll
irulusasiyuwam.dll
refobaju.dll
bdsl2.dll
muyinepa.dll
kbdnet.dll
robejaku.dll
lebenesa.dll
jelayube.dll
winmyy32.dll
bawawaza.dll
kekasika.dll
idolowun.dll
wahayaga.dll
pujosove.dll
evizavohiyesupa.dll
zorihali.dll
wehebopa.dll
yikuhawa.dll
bujiwofi.dll
fejolave.dll
kavumefe.dll
fezahoyu.dll
cmdial3.dll
alivevukov.dll
nahatona.dll
ixelinet.dll
iqugumamu.dll
kozeyizu.dll
idumowapupiy.dll
dmutil32.dll
relereni.dll
verabija.dll
mutelupo.dll
miduyevu.dll
bovekafu.dll
hesudobu.dll
VCL.dll
nageduge.dll
fehamito.dll
oyuwopoze.dll
mulirowo.dll
mivalivo.dll
zezowawi.dll
akuzivazoveraxif.dll
emihotepopeg.dll
etomemap.dll
dx8vb32.dll
norozuse.dll
rdolib.dll
papororo.dll
oderobifamaves.dll
dibawumi.dll
zofowoda.dll
ovamudutibofe.dll
potibubi.dll
bdaplgini.dll
uyuhapuhid.dll
sihosido.dll
dxva2C.dll
wujiwibe.dll
vabofoka.dll
palowaru.dll
omshtup.dll
tepepife.dll
afitegef.dll
hukubuhu.dll
zipavagi.dll
logomafe.dll
lepopoka.dll
ibitolet.dll
rigiwoti.dll
mokehohi.dll
bupuyafo.dll
tikatabi.dll
uzewerilupavid.dll
ijucahalevet.dll
debodoro.dll
sonuleme.dll
dijanumo.dll
vosevodi.dll
uhoyureg.dll
tijawani.dll
bopufeto.dll

slingshot malware processes to kill:

ree2.exe
onifr.exe
stuvwxy.exe
nl5.exe
pjdeya.exe
irxoe.exe
cajiw.exe
ree1.exe
realsvc.exe
mivi.exe
MySelf.exe
fwtrtuqtssd.exe
flsysio.exe
baka6.exe
nl4.exe
dwm.exe
beipq.exe
zs880000[1].exe
csrcs.exe
reqi.exe
svcchosst.exe
SystemAutorun.exe
qycu.exe
penis.exe
hepigalo.exe
ope2314.exe
fechme.exe
Ffodoa.exe
DisplaySwitch.exe
nl2.exe
iksuy.exe
Warn Support.exe
sdasda.exe
kylo.exe
zyex.exe
nl3.exe
ufdsvc.exe
207163515.exe
sysrc32.exe
photo_id.exe
odbn0.exe
nl6.exe
kulo.exe
icaqx.exe
ptidle.exe
comparevers.exe
pcpriv.exe
mcfg.exe
caese.exe
xydzyh.exe
vcnews.exe
Lxh.exe
asade.exe
RqAds.exe
kory.exe
wirepots.exe
xoipk.exe
poqii.exe
uclyv.exe
hnwqrys.exe
UnLoad.exe
rexsvc32.exe
AdobeSoftVaallupjhn.exe
ehczrw312.exe
1361163109.exe
roam five.exe
aim remote.exe
xipr.exe
pascmgp.exe
SerialsWorld.exe
winlo.exe
vybi.exe

Remove slingshot malware registry entries:

vmdetdhc.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad fsrpknov
Software\Microsoft\Internet Explorer\Explorer Bars {FCDEE81D-95A3-AE8A-D4FB-5A9FB8E32860}
Facegame
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify cxqmyibm
SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run xqe6lJLnN1
\Win14.exe
software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad xokvrpwg
SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad rwlfsdmk
\YUR131.exe
Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler {0ba3e00d-b660-46e6-a2db-2672ee82dc98}
Software\Microsoft\Internet Explorer\Explorer Bars {9CDB6E2A-B859-45BB-8F05-AF684301AB41}
Cognac
Sys4.exe
GetPack19
Software\Microsoft\Windows\CurrentVersion kdmsh.exe
C:\WINDOWS\System32\kdwls.exe
Somefox
\YUR5.exe
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run servises
GetPack21
\Win10.exe
\YURF.exe
cokx
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {BB4C402F-882A-4526-8C08-51278EA437C1}
\VIE5.exe
\YUR1.exe
\Win12.exe
F5JMWNZTHI
\YUR15.exe
\YUR18.exe
515.tmp
{157627A6-2A10-4aa1-B97F-90B8DC6F24AC}
%windir%\system32\kdswe.exe
{0389E53C-62CF-4CD6-9F4E-955A740E4385}
\VIE14.exe
%windir%\System32\kdwls.exe
SerialsWorld
\VIE2.exe
\YUR11.exe
{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {C14E6230-757D-4246-81CE-B34E2940C722}
\YUR30.exe
hlpproc
{4D4DB474-8435-4FA1-8D91-512C0CE1E931}
\YUR9.exe
Sys2.exe
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify ssqPhEVM
\YUR10.exe
BIND SUPPORT SEEK FIRST
memo site kind that
C:\WINDOWS\System32\kdmsh.exe
FixCamera
\YURA.exe
\YUR13.exe
SmartMon
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {D3CCFAF7-DF03-4E73-95EC-E5E139CC2BF2}
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE gi985993737
Sys1.exe
\YUR12E.exe
Online Alert Manager
\Win11.exe
\YUR20.exe
penis.exe
C:\WINDOWS\system32\kdswe.exe
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify __c0040F39
cont_mxlivemedia
Software\Microsoft\Windows\CurrentVersion kdid
xydzyh
bone thunk axis copy
\YUR2.exe
\YUR14.exe
Sys3.exe
\YUR12.exe
\YUR2C.exe
\YUR2A.exe
\YUR12F.exe
Captcha5
{E4785213-3EFE-4c26-A9B4-332440E31F6F}
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run andfor
\YUR2B.exe
\YURB.exe
\YURE.exe
lljyn_df
\YURD.exe
\Win13.exe
advap32
\YURC.exe
software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad tfnslopk
SOFTWARE\Microsoft\Internet Explorer\Toolbar {8E21DC20-6E4E-42B3-9796-244EC9385CEF}
\YUR6.exe
Long Internet Team Stupid
ptidle
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify nnnkiGvV
Software\Microsoft\Windows\CurrentVersion kdksc.exe
\YUR3.exe
{3BCF8450-D134-427E-AE9C-2A42CE8215CC}
SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad xrdwbfgn
{09E23F2C-ED1E-43FC-9AA1-1332162A35AE}
\YUR4.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad fdxbameg
\YUR8.exe
SOFTWARE\Microsoft\Internet Explorer\Toolbar {3B4EFB6A-06FD-40AC-B072-1FB7D1D456E8}
\VIE2F.exe
SOFTWARE\Microsoft\Internet Explorer\Toolbar {57776700-7BC8-47AC-B43E-99C24B015570}
Software\Microsoft\Internet Explorer\Explorer Bars {C2EC2654-52F0-3E63-9017-D0FA8FA79271}
%windir%\System32\kdmsh.exe
\YUR130.exe
ROAD ITCH AMOK PING
Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler {B2BA40A2-74F0-42BD-F434-12345A2C8953}
\YUR2D.exe
\VIE3.exe
Software\Microsoft\Internet Explorer\Explorer Bars {EB9539EB-598E-BCA7-3D4A-82F4F26E9738}
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.