Click on screenshot to zoom
Danger level 7
Type: Trojans
Common infection symptoms:
  • Connects to the internet without permission
  • Installs itself without permissions

slingshot malware

Slingshot malware happens to be an extremely malicious Trojan, which you must avoid at all costs. Doing so is crucial because this devious application is designed to act in an intrusive manner. Its developers usually use it to steal sensitive information from the affected computers. Also, this program could prove to be the primary reason other suspicious applications might enter your operating system without a lot of troubles. As you can imagine, having this Trojan up and running on your personal computer could lead to devastating outcomes, to put it lightly. If you want to find out more about its inner workings, be sure to read the rest of this article. Our researchers also present a few virtual security recommendations, which you must take to improve your virtual security. Besides all of that, we include a detailed removal guide, which you should use to delete slingshot malware in just a few simple steps.

It is important to note that it has been noticed that slingshot malware has affected more than 100 computers before being discovered. Most of these attacks were carried out in African and Middle Eastern countries. While that happens to be the case, it is crucial to understand that there are no guarantees that it will not spread elsewhere. Once this Trojan gains successful access to your operating system, it immediately starts doing its dirty work. Unfortunately, the majority of users are unable to identify and remove this program before it starts acting. That is so because it functions in a completely silent manner. First, it replaces your system's files with its own. The devious .dll file then downloads all the components of this malicious application and runs them. It is critical to note this Trojan consists of five different modules, and each of them has a distinct role. It has been identified that a module known as GollumApp has keylogging functionality; it can track your network information and steal passwords stored in your browser. The one entitled SsCB makes numerous screenshots, while ffproxy is designed to collect Firefox proxy settings and other configuration details. The other two modules known as Sfc2 and NeedleWatch are primarily used to inject files into your operating system and to disable Windows' files protection. On top of all that, it has been found out that this Trojan also has a downloader, which could be used to infect your operating system with other dangerous applications. To remove slingshot malware once and for all be sure to follow the instructions that you can find below.

It took some time before malware experts discovered how slingshot malware gains access to the operating system. During the extensive analysis, it has been discovered that malware developers got access to routers made by MikroTik and injected it with a malicious code, which initiated a download of a devious .dll file. Because of such distribution method, all the computers on the network could be infected this the Trojan in question. To keep your operating system free of this malware and other similar applications you need to take precautionary steps to improve your overall virtual security. We highly advise you to check if the network that you wish to connect to is safe and secure. Furthermore, you should know that cyber crooks also use spam email campaigns for distribution purposes. Therefore, we recommend refraining from all emails and email attachments that come your way from unknown third-parties. Also, remember to educate yourself about every application before downloading and installing it on your PC because malware developers are known to fool users by using hoax advertising tactics. Finally, and most importantly, every security-conscious user must have a professional antimalware tool active on their PC. Such a tool is the most important part of your virtual security because it is designed to detect and delete any virtual security threat automatically.

To remove slingshot malware, be sure to follow the instructions below. It is essential to execute this removal guide with care because a single mistake could have undesirable outcomes. Without even knowing you might leave data of this Trojan, which could be used to restore it silently. In other situations, a missed step could mean that this malicious program could continue working. Furthermore, it is important to note that manual removal is a complex task, which should be executed by advanced computer users. Malware researchers at our internal labs highly advise you to use a reliable antimalware tool for removal purposes because it is designed to delete slingshot malware and everything associated with it automatically.

How to remove slingshot malware from your PC

  1. Open your File Explorer.
  2. Go to C:\Windows\System32.
  3. Select a file called scesrv.dll and then replace it with the original one.
  4. Go to C:\Windows\SysWow64.
  5. Select a file called scesrv.dll and then replace it with the original one.
  6. Close your File Explorer.
  7. Restart your PC.
Download Spyware Removal Tool to Remove* slingshot malware
  • Quick & tested solution for slingshot malware removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove slingshot malware

Files associated with slingshot malware infection:

unapatax.dll
asycfil.dll
udihozazohec.dll
uqiwaceh.dll
%SystemRoot%\System32\rhc?????????
%UserProfile%\Application Data\643f??????????
afitegef.dll
%UserProfile%\Application Data\rhc?????????
aim remote.exe
yovalono.dll
realsvc.exe
ovamudutibofe.dll
idojapimogudoray.dll
eruzurow.dll
kavumefe.dll
oderobifamaves.dll
pivumedo.dll
tijawani.dll
sogidona.dll
fahokipa.dll
hekeyapi.dll
reqi.exe
sekisahi.dll
kedisuzo.dll
bufezeza.dll
dizubure.dll
fejolave.dll
bawawaza.dll
pokumala.dll
%ProgramFiles%
robejaku.dll
%UserProfile%\Application Data\thc?????????
%SystemRoot%\System32
wirepots.exe
AdobeSoftVaallupjhn.exe
dwm.exe
dx8vb32.dll
evejubet.dll
xipr.exe
asade.exe
dot3cfg32.dll
kalerazo.dll
penis.exe
%UserProfile%\Application Data\whc?????????
ClipHelp3xx.dll
uqojanecatevih.dll
%UserProfile%
uhoyureg.dll
fwtrtuqtssd.exe
%ProgramFiles%\bpph??????????
bopufeto.dll
iqugumamu.dll
%ProgramFiles%\643f??????????
dxva2C.dll
svcchosst.exe
ehczrw312.exe
eloheseweriquyi.dll
uheludeje.dll
lepopoka.dll
csrcs.exe
ofriasc.dll
yikuhawa.dll
pujosove.dll
sesanujo.dll
nevoputo.dll
207163515.exe
vybi.exe
zemupalu.dll
AcroIEHelpe022.dll
digiwet.dll
uzewerilupavid.dll
mivalivo.dll
nutowuko.dll
caese.exe
icocalolacihir.dll
etomemap.dll
icaqx.exe
muyinepa.dll
irulusasiyuwam.dll
lopibeki.dll
%SystemRoot%\System32\thc?????????
mokehohi.dll
jahasike.dll
ptidle.exe
alivevukov.dll
srenum.sys
ajuquqoqepoqu.dll
dibawumi.dll
kekasika.dll
kbdnet.dll
%UserProfile%\thc?????????
%UserProfile%\rhc?????????
%UserProfile%\Application Data\blphc?????????
qycu.exe
uclyv.exe
pascmgp.exe
junefare.dll
dmutil32.dll
fozusayo.dll
dodohovo.dll
wahayaga.dll
vubabuku.dll
Warn Support.exe
comparevers.exe
uyefesujoxumu.dll
jimofiji.dll
%UserProfile%\bpph??????????
xoipk.exe
oviyukebicitaq.dll
doriyubi.dll
Lxh.exe
bovekafu.dll
tipifipo.dll
ijusuyanami.dll
%SystemRoot%\System32\lphc?????????
onifr.exe
mafuyiha.dll
vopereso.dll
fehamito.dll
hnwqrys.exe
miduyevu.dll
pcpriv.exe
sgpron.dll
PowerJa.ask
uqogumamumuse.dll
akuzivazoveraxif.dll
togojaze.dll
zyex.exe
nupotuku.dll
%ProgramFiles%\thc?????????
juhalobo.dll
iksuy.exe
bdsyslink.dll
zezowawi.dll
rigiwoti.dll
futewege.dll
MySelf.exe
verabija.dll
palowaru.dll
norozuse.dll
nuviyapi.dll
oyuwopoze.dll
jelayube.dll
%ProgramFiles%\rhc?????????
ijucahalevet.dll
kory.exe
idolowun.dll
%ProgramFiles%\phc?????????
wujiwibe.dll
topapope.dll
dijanumo.dll
oqifubeqixi.dll
balomane.dll
yosineku.dll
%ProgramFiles%\blphc?????????
%ProgramFiles%\pphc?????????
nahatona.dll
sonuleme.dll
%UserProfile%\blphc?????????
omshtup.dll
juriyuyi.dll
kozeyizu.dll
cajiw.exe
debodoro.dll
nl5.exe
%UserProfile%\Application Data\bpph??????????
rdolib.dll
%SystemRoot%\System32\643f??????????
sihosido.dll
%UserProfile%\whc?????????
kurtapt24@yahoo.com
ree1.exe
sysrc32.exe
fechme.exe
zelovumi.dll
mulirowo.dll
zs880000[1].exe
nl4.exe
%SystemRoot%\System32\phc?????????
kylo.exe
winlo.exe
nohisoye.dll
%UserProfile%\Application Data\phc?????????
mukejowe.dll
asvdxl.dll
nupanogo.dll
yowujeje.dll
bisevona.dll
nageduge.dll
Ffodoa.exe
poqii.exe
VCL.dll
vcnews.exe
bupuyafo.dll
kdpini.dll
nl3.exe
sumonibe.dll
ope2314.exe
tepepife.dll
pehuraba.dll
%UserProfile%\Application Data\pphc?????????
kifupiza.dll
%ProgramFiles%\whc?????????
wisegava.dll
barijatu.dll
rexsvc32.exe
kafunepi.dll
nl6.exe
logomafe.dll
SerialsWorld.exe
hepigalo.exe
fenofaki.dll
roam five.exe
yopalimi.dll
tikatabi.dll
stuvwxy.exe
evizavohiyesupa.dll
baka6.exe
livukafa.dll
lewiyidi.dll
ufdsvc.exe
DisplaySwitch.exe
bdaplgini.dll
SystemAutorun.exe
nsx23.dll
RqAds.exe
emihotepopeg.dll
relereni.dll
mejiyolo.dll
pjdeya.exe
akihovojamaz.dll
itufijorece.dll
%UserProfile%\643f??????????
%UserProfile%\pphc?????????
%TEMP%
luyehije.dll
%ProgramFiles%\lphc?????????
%SystemRoot%\System32\whc?????????
KBDURsr.dll
sdasda.exe
hovebipu.dll
flsysio.exe
zofowoda.dll
uvojigulukacega.dll
irxoe.exe
atl7.dll
%UserProfile%\Application Data
sujibiwi.dll
aboheraj.dll
%SystemRoot%\System32\blphc?????????
%SystemRoot%\System32\bpph??????????
morugawe.dll
winmyy32.dll
%UserProfile%\Application Data\lphc?????????
yamanewa.dll
nobajanu.dll
obaluqizevax.dll
vabofoka.dll
refobaju.dll
ufimixefenoy.dll
delidubu.dll
fezahoyu.dll
wehebopa.dll
%SystemRoot%\System32\pphc?????????
hoyuvuki.dll
mivi.exe
photo_id.exe
zarebeba.dll
zorihali.dll
uvumaxeqa.dll
nl2.exe
xydzyh.exe
papororo.dll
wisysvi.dll
ree2.exe
%UserProfile%\phc?????????
bdsl2.dll
ibitolet.dll
idumowapupiy.dll
iyupodovujepope.dll
bujiwofi.dll
kulo.exe
vupesasu.dll
kusers.dll
UnLoad.exe
mcfg.exe
1361163109.exe
zipavagi.dll
hesudobu.dll
potibubi.dll
lebenesa.dll
%UserProfile%\lphc?????????
penipure.dll
cmdial3.dll
yatodimi.dll
ugavisidu.dll
odbn0.exe
uyuhapuhid.dll
ixelinet.dll
beipq.exe

slingshot malware DLL's to remove:

hoyuvuki.dll
yowujeje.dll
bawawaza.dll
eruzurow.dll
pokumala.dll
bdaplgini.dll
hekeyapi.dll
livukafa.dll
tijawani.dll
afitegef.dll
yosineku.dll
nageduge.dll
mejiyolo.dll
etomemap.dll
juhalobo.dll
nobajanu.dll
jelayube.dll
atl7.dll
zezowawi.dll
futewege.dll
bisevona.dll
uhoyureg.dll
idumowapupiy.dll
jahasike.dll
akuzivazoveraxif.dll
sekisahi.dll
ibitolet.dll
ajuquqoqepoqu.dll
wehebopa.dll
lepopoka.dll
aboheraj.dll
fahokipa.dll
sihosido.dll
yovalono.dll
uyuhapuhid.dll
dot3cfg32.dll
papororo.dll
luyehije.dll
zorihali.dll
fehamito.dll
mulirowo.dll
topapope.dll
muyinepa.dll
vupesasu.dll
kekasika.dll
mafuyiha.dll
hovebipu.dll
robejaku.dll
ufimixefenoy.dll
sujibiwi.dll
nahatona.dll
oyuwopoze.dll
uqogumamumuse.dll
nutowuko.dll
pujosove.dll
wahayaga.dll
alivevukov.dll
mukejowe.dll
oqifubeqixi.dll
winmyy32.dll
dxva2C.dll
nuviyapi.dll
kedisuzo.dll
logomafe.dll
bopufeto.dll
wujiwibe.dll
emihotepopeg.dll
rdolib.dll
miduyevu.dll
potibubi.dll
idolowun.dll
norozuse.dll
digiwet.dll
uvumaxeqa.dll
pivumedo.dll
uheludeje.dll
oviyukebicitaq.dll
verabija.dll
balomane.dll
ugavisidu.dll
yatodimi.dll
zelovumi.dll
ixelinet.dll
mivalivo.dll
dizubure.dll
debodoro.dll
rigiwoti.dll
dmutil32.dll
KBDURsr.dll
iyupodovujepope.dll
wisegava.dll
zemupalu.dll
ijusuyanami.dll
nohisoye.dll
eloheseweriquyi.dll
sumonibe.dll
unapatax.dll
asvdxl.dll
evizavohiyesupa.dll
kozeyizu.dll
wisysvi.dll
nevoputo.dll
uqojanecatevih.dll
vabofoka.dll
VCL.dll
lewiyidi.dll
kifupiza.dll
bdsl2.dll
zipavagi.dll
ofriasc.dll
nsx23.dll
mokehohi.dll
akihovojamaz.dll
bufezeza.dll
juriyuyi.dll
pehuraba.dll
AcroIEHelpe022.dll
evejubet.dll
junefare.dll
kavumefe.dll
vopereso.dll
kalerazo.dll
kdpini.dll
fezahoyu.dll
hesudobu.dll
delidubu.dll
barijatu.dll
bupuyafo.dll
sogidona.dll
sesanujo.dll
fenofaki.dll
fozusayo.dll
sonuleme.dll
uyefesujoxumu.dll
vubabuku.dll
udihozazohec.dll
irulusasiyuwam.dll
dibawumi.dll
lopibeki.dll
dx8vb32.dll
idojapimogudoray.dll
zarebeba.dll
togojaze.dll
uzewerilupavid.dll
palowaru.dll
kbdnet.dll
ClipHelp3xx.dll
icocalolacihir.dll
bovekafu.dll
ovamudutibofe.dll
uqiwaceh.dll
itufijorece.dll
yikuhawa.dll
tikatabi.dll
tepepife.dll
kusers.dll
yopalimi.dll
nupanogo.dll
fejolave.dll
yamanewa.dll
uvojigulukacega.dll
bdsyslink.dll
zofowoda.dll
omshtup.dll
iqugumamu.dll
dodohovo.dll
cmdial3.dll
ijucahalevet.dll
jimofiji.dll
morugawe.dll
dijanumo.dll
refobaju.dll
sgpron.dll
nupotuku.dll
obaluqizevax.dll
kafunepi.dll
oderobifamaves.dll
doriyubi.dll
bujiwofi.dll
asycfil.dll
penipure.dll
relereni.dll
lebenesa.dll
tipifipo.dll

slingshot malware processes to kill:

ope2314.exe
207163515.exe
odbn0.exe
xoipk.exe
AdobeSoftVaallupjhn.exe
irxoe.exe
nl3.exe
iksuy.exe
kylo.exe
reqi.exe
zs880000[1].exe
ptidle.exe
hnwqrys.exe
cajiw.exe
svcchosst.exe
wirepots.exe
winlo.exe
photo_id.exe
realsvc.exe
SerialsWorld.exe
aim remote.exe
kulo.exe
1361163109.exe
vybi.exe
zyex.exe
comparevers.exe
mivi.exe
Lxh.exe
sdasda.exe
poqii.exe
caese.exe
asade.exe
nl6.exe
vcnews.exe
MySelf.exe
sysrc32.exe
icaqx.exe
pcpriv.exe
Ffodoa.exe
dwm.exe
fechme.exe
ree1.exe
baka6.exe
DisplaySwitch.exe
uclyv.exe
nl4.exe
fwtrtuqtssd.exe
hepigalo.exe
mcfg.exe
pjdeya.exe
beipq.exe
xydzyh.exe
stuvwxy.exe
ehczrw312.exe
rexsvc32.exe
Warn Support.exe
ree2.exe
roam five.exe
kory.exe
RqAds.exe
xipr.exe
SystemAutorun.exe
csrcs.exe
flsysio.exe
UnLoad.exe
pascmgp.exe
nl2.exe
onifr.exe
nl5.exe
penis.exe
qycu.exe
ufdsvc.exe

Remove slingshot malware registry entries:

\YURA.exe
C:\WINDOWS\system32\kdswe.exe
\Win13.exe
Software\Microsoft\Windows\CurrentVersion kdmsh.exe
GetPack19
Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler {0ba3e00d-b660-46e6-a2db-2672ee82dc98}
Software\Microsoft\Windows\CurrentVersion kdksc.exe
Software\Microsoft\Internet Explorer\Explorer Bars {FCDEE81D-95A3-AE8A-D4FB-5A9FB8E32860}
\YUR30.exe
{3BCF8450-D134-427E-AE9C-2A42CE8215CC}
penis.exe
%windir%\system32\kdswe.exe
{09E23F2C-ED1E-43FC-9AA1-1332162A35AE}
\YUR5.exe
{0389E53C-62CF-4CD6-9F4E-955A740E4385}
ptidle
Sys4.exe
Captcha5
\YURD.exe
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify nnnkiGvV
\YUR3.exe
\YUR9.exe
cont_mxlivemedia
\VIE3.exe
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE gi985993737
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run andfor
Sys3.exe
C:\WINDOWS\System32\kdmsh.exe
\YURC.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run xqe6lJLnN1
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify __c0040F39
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {C14E6230-757D-4246-81CE-B34E2940C722}
memo site kind that
Software\Microsoft\Internet Explorer\Explorer Bars {C2EC2654-52F0-3E63-9017-D0FA8FA79271}
Somefox
\YUR2.exe
{E4785213-3EFE-4c26-A9B4-332440E31F6F}
515.tmp
advap32
\YUR14.exe
SerialsWorld
\VIE14.exe
software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad xokvrpwg
Cognac
\Win10.exe
SmartMon
bone thunk axis copy
SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad xrdwbfgn
\YURE.exe
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify ssqPhEVM
\YUR4.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad rwlfsdmk
{4D4DB474-8435-4FA1-8D91-512C0CE1E931}
Facegame
\YUR2C.exe
Long Internet Team Stupid
cokx
lljyn_df
Online Alert Manager
{78B578D7-BCE1-4d83-9CD4-195BC34D8CB3}
\YUR12F.exe
\YUR10.exe
\YUR11.exe
Sys1.exe
\YUR20.exe
SOFTWARE\Microsoft\Internet Explorer\Toolbar {3B4EFB6A-06FD-40AC-B072-1FB7D1D456E8}
software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad tfnslopk
F5JMWNZTHI
\YUR18.exe
\Win11.exe
\YURF.exe
\Win12.exe
SOFTWARE\Microsoft\Internet Explorer\Toolbar {8E21DC20-6E4E-42B3-9796-244EC9385CEF}
%windir%\System32\kdmsh.exe
\YUR130.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad fsrpknov
Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler {B2BA40A2-74F0-42BD-F434-12345A2C8953}
SOFTWARE\Microsoft\Internet Explorer\Toolbar {57776700-7BC8-47AC-B43E-99C24B015570}
\YUR2B.exe
\YUR12E.exe
Sys2.exe
\YUR6.exe
\YUR2D.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad fdxbameg
hlpproc
{157627A6-2A10-4aa1-B97F-90B8DC6F24AC}
Software\Microsoft\Internet Explorer\Explorer Bars {EB9539EB-598E-BCA7-3D4A-82F4F26E9738}
%windir%\System32\kdwls.exe
\YURB.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {BB4C402F-882A-4526-8C08-51278EA437C1}
Software\Microsoft\Internet Explorer\Explorer Bars {9CDB6E2A-B859-45BB-8F05-AF684301AB41}
GetPack21
C:\WINDOWS\System32\kdwls.exe
\YUR15.exe
\YUR2A.exe
vmdetdhc.exe
xydzyh
\YUR131.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {D3CCFAF7-DF03-4E73-95EC-E5E139CC2BF2}
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify cxqmyibm
\VIE2.exe
Software\Microsoft\Windows\CurrentVersion kdid
\Win14.exe
\VIE5.exe
\YUR12.exe
BIND SUPPORT SEEK FIRST
\VIE2F.exe
\YUR8.exe
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run servises
\YUR1.exe
FixCamera
ROAD ITCH AMOK PING
\YUR13.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.