Home Malware Programs Adware Shopperz Ads

Shopperz Ads

Posted: November 12, 2014

Threat Metric

Ranking: 3,590
Threat Level: 2/10
Infected PCs: 217,794
First Seen: November 11, 2014
Last Seen: March 7, 2025
OS(es) Affected: Windows

Shopperz is another adware-supported browser extension created for the purpose of better online shopping experience. In reality, it is just the opposite as this application can cause your browser to behave in a strange way. For example, Shopperz may display advertisements that can be under the shape of discounts, coupons, deals, promo codes. According to leading threat specialists, Shopperz may not be a virus, but it is one annoying browser add-on, and they advise users to find a way and fix their system by removing files related to Shopperz.

Aliases

Trojan/Win32.TSGeneric [Antiy-AVL]Adware.Shopper.989 [DrWeb]Win.Adware.Netfilter-722 [ClamAV]W64/S-da439d85!Eldorado [F-Prot]Generic.4D9 [AVG]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\Vikonefucu\Vikonefucu.exe File name: Vikonefucu.exe
Size: 170.49 KB (170496 bytes)
MD5: e5b831d75cfdfd9b34095f408565e8d5
Detection count: 309
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Vikonefucu
Group: Malware file
Last Updated: March 31, 2020
%APPDATA%\Poczho\Poczho.exe File name: Poczho.exe
Size: 170.49 KB (170496 bytes)
MD5: 776cf85225fa73178868f3c4723fc605
Detection count: 166
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Poczho
Group: Malware file
Last Updated: July 6, 2016
%APPDATA%\Jhunh\Jhunh.exe File name: Jhunh.exe
Size: 170.49 KB (170496 bytes)
MD5: fa71455facfcd49e5bc931a4f39e1b64
Detection count: 148
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Jhunh
Group: Malware file
Last Updated: July 6, 2016
%APPDATA%\Guecelocfi\Guecelocfi.exe File name: Guecelocfi.exe
Size: 170.49 KB (170496 bytes)
MD5: 41d5a52f5b523d3317bb0c137cecb770
Detection count: 131
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Guecelocfi
Group: Malware file
Last Updated: July 6, 2016
%APPDATA%\Reicf\Reicf.exe File name: Reicf.exe
Size: 170.49 KB (170496 bytes)
MD5: 9f17f0833e797e4faf1249cc8f11c22a
Detection count: 112
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Reicf
Group: Malware file
Last Updated: July 6, 2016
%APPDATA%\Xuildauy\Xuildauy.exe File name: Xuildauy.exe
Size: 170.49 KB (170496 bytes)
MD5: 718c2e5b28a83cfc06c713104537c8e4
Detection count: 96
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Xuildauy
Group: Malware file
Last Updated: July 6, 2016
%PROGRAMFILES%\Wujsarkabra\Imhti.bat File name: Imhti.bat
Size: 80B (80 bytes)
MD5: 036ee090512f608ad08b0c63bc8c224e
Detection count: 90
File type: Batch file
Mime Type: unknown/bat
Path: %PROGRAMFILES%\Wujsarkabra
Group: Malware file
Last Updated: April 27, 2016
%PROGRAMFILES%\Gegr\Wasrho.bat File name: Wasrho.bat
Size: 80B (80 bytes)
MD5: f09eb9e3434542c110b148cba578e217
Detection count: 73
File type: Batch file
Mime Type: unknown/bat
Path: %PROGRAMFILES%\Gegr
Group: Malware file
Last Updated: April 27, 2016
%APPDATA%\Fidelahaou\Fidelahaou.exe File name: Fidelahaou.exe
Size: 170.49 KB (170496 bytes)
MD5: 6a9e04b90b82fb35b320cb7a0c42e88f
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Fidelahaou
Group: Malware file
Last Updated: July 6, 2016
%APPDATA%\Voakcygb\Voakcygb.exe File name: Voakcygb.exe
Size: 170.49 KB (170496 bytes)
MD5: 8591dfe35faa10a726a4370cb46854b9
Detection count: 68
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Voakcygb
Group: Malware file
Last Updated: July 6, 2016
%APPDATA%\Ruekwuwkic\Ruekwuwkic.exe File name: Ruekwuwkic.exe
Size: 170.49 KB (170496 bytes)
MD5: 8e490ee3fe2672a583b81e7ef3aa205f
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Ruekwuwkic
Group: Malware file
Last Updated: July 6, 2016
%APPDATA%\Riidam\Riidam.exe File name: Riidam.exe
Size: 170.49 KB (170496 bytes)
MD5: 5e23b598443ba8bceb049bb3f4f89da8
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Riidam
Group: Malware file
Last Updated: July 6, 2016
%APPDATA%\Meifpu\Meifpu.exe File name: Meifpu.exe
Size: 170.49 KB (170496 bytes)
MD5: 865d6e67f7f7140b2b7f379745525b90
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Meifpu
Group: Malware file
Last Updated: July 6, 2016
%PROGRAMFILES%\Aolaffelf\Kibof.bat File name: Kibof.bat
Size: 80B (80 bytes)
MD5: fe90f30226c25f025b0a26d0025bd8b6
Detection count: 40
File type: Batch file
Mime Type: unknown/bat
Path: %PROGRAMFILES%\Aolaffelf
Group: Malware file
Last Updated: April 27, 2016
%PROGRAMFILES%\Buajuw\Apolraku.bat File name: Apolraku.bat
Size: 80B (80 bytes)
MD5: c4b3ab8bbea36db07b66bed1b97d76bf
Detection count: 31
File type: Batch file
Mime Type: unknown/bat
Path: %PROGRAMFILES%\Buajuw
Group: Malware file
Last Updated: April 27, 2016
%PROGRAMFILES%\Wapgywceamcimk\Guawr.exe File name: Guawr.exe
Size: 272.25 KB (272256 bytes)
MD5: 109d93c3b43a781f168ca9154ecaace6
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Wapgywceamcimk
Group: Malware file
Last Updated: May 10, 2016
%PROGRAMFILES%\Wapgywceamcimk\Avobahhr.exe File name: Avobahhr.exe
Size: 275.32 KB (275328 bytes)
MD5: 64c2a2551c04411fe508229cf203b48d
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Wapgywceamcimk
Group: Malware file
Last Updated: May 10, 2016
%PROGRAMFILES%\Wapgywceamcimk\ZuxkEjulpam.exe File name: ZuxkEjulpam.exe
Size: 536.96 KB (536960 bytes)
MD5: a023dad8b8008d0a76cae74777ff4d52
Detection count: 11
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Wapgywceamcimk
Group: Malware file
Last Updated: May 10, 2016
%PROGRAMFILES%\Lyje\Khmao.bat File name: Khmao.bat
Size: 80B (80 bytes)
MD5: a1fc9232f98243c7a288fc6f45b1e12c
Detection count: 9
File type: Batch file
Mime Type: unknown/bat
Path: %PROGRAMFILES%\Lyje
Group: Malware file
Last Updated: April 27, 2016
\??\C:\Windows\system32\Drivers\bsdpf64.sys File name: bsdpf64.sys
Size: 27.45 KB (27456 bytes)
MD5: 828b1d1e22527ada4a64ac1e68aa3852
Detection count: 9
File type: System file
Mime Type: unknown/sys
Path: \??\C:\Windows\system32\Drivers
Group: Malware file
Last Updated: April 28, 2016
\??\C:\Windows\system32\Drivers\bsdpr64.sys File name: bsdpr64.sys
Size: 26.94 KB (26944 bytes)
MD5: d55540caa966d5af2c5d462f9c7ca3ab
Detection count: 9
File type: System file
Mime Type: unknown/sys
Path: \??\C:\Windows\system32\Drivers
Group: Malware file
Last Updated: April 28, 2016
%PROGRAMFILES%\Wapgywceamcimk\Gofva.exe File name: Gofva.exe
Size: 559.1 KB (559104 bytes)
MD5: a75ca9cdf17d7392f2a75b4e1c39aaf1
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Wapgywceamcimk
Group: Malware file
Last Updated: May 10, 2016
%PROGRAMFILES%\Wapgywceamcimk\Gofva64.exe File name: Gofva64.exe
Size: 710.01 KB (710016 bytes)
MD5: 3854c79735a76783213619bc90476e04
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Wapgywceamcimk
Group: Malware file
Last Updated: May 10, 2016
%PROGRAMFILES%\Lisgitiiokh\Worjayd.bat File name: Worjayd.bat
Size: 80B (80 bytes)
MD5: c8fdddf35291296ea14a3c1dcf860aac
Detection count: 5
File type: Batch file
Mime Type: unknown/bat
Path: %PROGRAMFILES%\Lisgitiiokh
Group: Malware file
Last Updated: April 27, 2016
%PROGRAMFILES%\Vavj\Onujjion.bat File name: Onujjion.bat
Size: 80B (80 bytes)
MD5: a67929b53b9c3eda08601387e88a6212
Detection count: 5
File type: Batch file
Mime Type: unknown/bat
Path: %PROGRAMFILES%\Vavj
Group: Malware file
Last Updated: April 27, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{02FBE316-E0DD-4DB4-9FF7-44E3028A644A}{08ACFB57-8187-47f0-AF93-56360D03634A}{0A19D4F9-60BF-4471-88B1-FF4EC3168DEC}{10E75EDD-1630-4E07-9CF8-B318A7717FCE}{13189CA1-C2B1-4EE9-aE46-CE2C0520053D}{14EF423E-3EE8-44AE-9337-07AC3F27B744}{1664D439-C936-4560-8B1D-166CEAE021E6}{21186475-d4df-43e2-9bba-0b52c00e0e27}{2395B860-45E4-42fd-96E6-50BA597C1C42}{35C4637C-4CF8-4C5D-864C-5239EEFEB0ED}{3C2C21F7-FDB6-4b10-B605-FA4A281E3016}{3c9ce603-44cc-4997-a166-239e6186c6ef}{3CF50C82-4C4B-43e9-B1B2-15CB1BD0C193}{40064F2B-BE74-40c0-B30F-1AF103872638}{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}{4831289C-54C7-4CB5-849D-33E0350B93F7}{483B3354-1399-4CE9-82FA-CFACA360B465}{535b69cf-44f6-4c9f-96b1-b5adb65c582d}{561EF67F-A0E1-4EF0-87BB-87AB9DA40665}{5E8E5F49-3024-4E2C-80EC-BE28C81C3565}{6F1EC027-290F-499f-BB58-BF04BA67C2B3}{79562DD1-F962-4b2e-ADF4-434C5848F911}{7D8DAE88-BC05-4578-8C29-E541FFBA5757}{7EE956E9-3E36-42DD-8A60-FD83085FD20D}{87AE2985-0835-4ABD-8398-D49B0BFCCA99}{9c760b40-4718-40c3-a68d-2e4f21591d62}{A9582D7B-F24A-441D-9D26-450D58F3CD17}{AD3B3B31-21A9-44E7-8112-DF70373F3353}{B1C01F05-691E-4402-878B-A409D4D489CE}{B1E7C398-824A-4CB9-8D98-DF02E560EA02}{B5C4833B-847B-49CD-8EBE-CDD9B43C882F}{c3357769-3570-481c-9554-97865d9054e4}{C74AB308-BA97-42f6-BB20-00E0868F52FB}{cc89419d-fcd5-4a6b-aca2-09043448db22}{d0174004-bb12-464b-b666-9ba9bdbd750a}{DD50911B-2767-4061-9B55-EF5F0AAB5A79}{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}{EE0D8859-2ED4-4B0D-9812-16865B9AFD65}{F525CC93-970E-4841-8524-C7A087F4B650}{F67329C7-6D17-4b82-913A-2646014A54A3}Regexp file mask%WINDIR%\System32\drivers\cherimoya.sys%WinDir%\System32\JapgaeifmOff.ini%WinDir%\System32\Ooteeotoor.ini%WinDir%\System32\OoteeotoorOff.ini%WinDir%\System32\Peakoar64.dll%WINDIR%\System32\Tasks\omrUpdater%windir%\System32\Tasks\Papuir%WINDIR%\System32\Tasks\Uwewbiut%WINDIR%\System32\Uiviuuj64.dll%WINDIR%\System32\UiviuujOff.ini%WinDir%\sysWOW64\Peakoar.dll%WINDIR%\SysWOW64\Uiviuuj.ini%WINDIR%\SysWOW64\UiviuujOff.iniHKEY..\..\..\..{RegistryKeys}SOFTWARE\AiduwbSOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}SOFTWARE\Classes\Extension.boponSOFTWARE\Classes\Extension.bopon.1SOFTWARE\Classes\Extension.GwynSOFTWARE\Classes\Extension.Gwyn.1SOFTWARE\Classes\Extension.HopjulSOFTWARE\Classes\Extension.Hopjul.1SOFTWARE\Classes\Extension.tzahSOFTWARE\Classes\Extension.YhhbeSOFTWARE\Classes\Extension.Yhhbe.1Software\Classes\Software\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}Software\Classes\Software\{79562DD1-F962-4b2e-ADF4-434C5848F911}Software\Classes\Software\{A7FC5860-2A3A-4554-AFB1-C7F4DD432693}Software\Classes\Software\{F51B5B89-A3AC-4BD6-b917-556C2DF511BC}Software\Classes\Software\{F67329C7-6D17-4b82-913A-2646014A54A3}SOFTWARE\Classes\Software\{FD93FD05-00A8-4EAB-8202-C0D95D68B940}Software\Microsoft\Internet Explorer\Approved Extensions\{05B963BD-F46D-4117-b829-0F3FA2D12570}Software\Microsoft\Internet Explorer\Approved Extensions\{0AB1A938-7792-4761-8861-1DD8DEE5005E}Software\Microsoft\Internet Explorer\Approved Extensions\{318d2d55-9ce3-446e-8640-a43be68a550f}Software\Microsoft\Internet Explorer\Approved Extensions\{3C2C21F7-FDB6-4b10-B605-FA4A281E3016}Software\Microsoft\Internet Explorer\Approved Extensions\{3c9ce603-44cc-4997-a166-239e6186c6ef}Software\Microsoft\Internet Explorer\Approved Extensions\{4D45295D-47E1-44EB-864C-5F3C780BD277}Software\Microsoft\Internet Explorer\Approved Extensions\{50B41FA7-CDB0-4E1A-85AA-773B4CA2E953}Software\Microsoft\Internet Explorer\Approved Extensions\{513EEBEC-206E-4F41-96B8-E26C3487E484}Software\Microsoft\Internet Explorer\Approved Extensions\{5588FB9F-0CBF-4189-99E6-EBD06C0E02AC}Software\Microsoft\Internet Explorer\Approved Extensions\{6CA285EC-02EF-46CA-8F00-79D80E4E4342}Software\Microsoft\Internet Explorer\Approved Extensions\{709C6CF2-4B76-47BF-8569-F9C7874C9B9C}SOFTWARE\Microsoft\Internet Explorer\Approved Extensions\{855A8483-AC9C-43D2-bBBD-65042C5523F0}Software\Microsoft\Internet Explorer\Approved Extensions\{9A03A02C-5764-4CBB-8495-34007D94AC10}Software\Microsoft\Internet Explorer\Approved Extensions\{A499593E-BDA6-4C3D-94AA-368852A8C549}Software\Microsoft\Internet Explorer\Approved Extensions\{AAE3CAD1-5057-47E6-8CB8-D84EEB67D91C}Software\Microsoft\Internet Explorer\Approved Extensions\{B0F49364-D378-4B0F-8E36-772579148834}Software\Microsoft\Internet Explorer\Approved Extensions\{B1E7C398-824A-4CB9-8D98-DF02E560EA02}Software\Microsoft\Internet Explorer\Approved Extensions\{B73D547E-7542-4D5C-9CCF-02D21B4219D3}SOFTWARE\Microsoft\Internet Explorer\Approved Extensions\{C74AB308-BA97-42f6-BB20-00E0868F52FB}Software\Microsoft\Internet Explorer\Approved Extensions\{D51D4235-9CAC-405A-9D6E-F0A3EDCC574C}SOFTWARE\Microsoft\Internet Explorer\Approved Extensions\{D596F7A5-6563-413E-bCCB-B6D70AC596BE}Software\Microsoft\Internet Explorer\Approved Extensions\{F02D0B85-9567-4932-828C-9A8BCE789C7B}Software\Microsoft\Internet Explorer\Approved Extensions\{F1326CAB-2D6A-475F-9A4E-4BFD5CB3E920}Software\Microsoft\Internet Explorer\Approved Extensions\{F4B7F5C6-C1F2-4AD0-9DD5-687682B2A363}Software\Microsoft\Internet Explorer\Approved Extensions\{F525CC93-970E-4841-8524-C7A087F4B650}Software\Microsoft\Internet Explorer\Approved Extensions\{F5E7D8E6-CFDB-44A0-89D5-214311E16323}Software\Microsoft\Internet Explorer\Approved Extensions\{F77B2884-FB1D-4239-a847-D487941CE9A2}Software\Microsoft\Internet Explorer\Stats\{3C2C21F7-FDB6-4b10-B605-FA4A281E3016}Software\Microsoft\Internet Explorer\Stats\{B1E7C398-824A-4CB9-8D98-DF02E560EA02}SOFTWARE\Microsoft\Internet Explorer\Stats\{C74AB308-BA97-42f6-BB20-00E0868F52FB}SOFTWARE\Microsoft\Internet Explorer\Stats\{F525CC93-970E-4841-8524-C7A087F4B650}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\omrUpdaterSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3C2C21F7-FDB6-4b10-B605-FA4A281E3016}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B1E7C398-824A-4CB9-8D98-DF02E560EA02}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F525CC93-970E-4841-8524-C7A087F4B650}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3C2C21F7-FDB6-4B10-B605-FA4A281E3016}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\shopperzSOFTWARE\Microsoft\Windows\CurrentVersion\Run\shopperz64SOFTWARE\Mozilla\Firefox\Extensions\{318d2d55-9ce3-446e-8640-a43be68a550f}SOFTWARE\Mozilla\Firefox\Extensions\{3C2C21F7-FDB6-4b10-B605-FA4A281E3016}SOFTWARE\Mozilla\Firefox\Extensions\{970050F4-B21B-4c84-ACAB-DFEB867A4776}SOFTWARE\Mozilla\Firefox\Extensions\{C74AB308-BA97-42f6-BB20-00E0868F52FB}SOFTWARE\shopper-zSOFTWARE\shopperzSOFTWARE\Wow6432Node\AiduwbSOFTWARE\Wow6432Node\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}SOFTWARE\Wow6432Node\KajajugtSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B1E7C398-824A-4CB9-8D98-DF02E560EA02}SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F525CC93-970E-4841-8524-C7A087F4B650}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\{318d2d55-9ce3-446e-8640-a43be68a550f}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\{3C2C21F7-FDB6-4b10-B605-FA4A281E3016}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\{3c9ce603-44cc-4997-a166-239e6186c6ef}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\{970050F4-B21B-4c84-ACAB-DFEB867A4776}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\{C74AB308-BA97-42f6-BB20-00E0868F52FB}SOFTWARE\Wow6432Node\shopper-zSOFTWARE\Wow6432Node\shopperzSOFTWARE\Wow6432Node\YhidSOFTWARE\YhidSoftware\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}Software\{58F2BB99-F9AF-415D-b3B0-E931E94FADA3}Software\{F51B5B89-A3AC-4BD6-b917-556C2DF511BC}Software\{FD93FD05-00A8-4EAB-8202-C0D95D68B940}SYSTEM\ControlSet001\Control\SafeBoot\Minimal\bsdpf64.sysSYSTEM\ControlSet001\Control\SafeBoot\Minimal\bsdpr64.sysSYSTEM\ControlSet001\Control\SafeBoot\Network\bsdpf64.sysSYSTEM\ControlSet001\Control\SafeBoot\Network\bsdpr64.sysSYSTEM\ControlSet001\Enum\Root\LEGACY_BSDPF64SYSTEM\ControlSet001\Enum\Root\LEGACY_BSDPR64SYSTEM\ControlSet001\Enum\Root\LEGACY_CHERIMOYASYSTEM\ControlSet001\services\05B93BAB-FAE5-44A8-9846-753385F00C07SYSTEM\ControlSet001\services\8dadad2f-d980-4b45-ab50-b9af125601a7SYSTEM\ControlSet001\services\cherimoyaSYSTEM\ControlSet001\services\csrccSYSTEM\ControlSet001\services\DifkuCiabfSYSTEM\ControlSet001\services\shopper-z UpdaterSYSTEM\ControlSet001\services\shopperz UpdaterSYSTEM\ControlSet002\Control\SafeBoot\Minimal\bsdpf64.sysSYSTEM\ControlSet002\Control\SafeBoot\Minimal\bsdpr64.sysSYSTEM\ControlSet002\Control\SafeBoot\Network\bsdpf64.sysSYSTEM\ControlSet002\Control\SafeBoot\Network\bsdpr64.sysSYSTEM\ControlSet002\Enum\Root\LEGACY_BSDPF64SYSTEM\ControlSet002\Enum\Root\LEGACY_BSDPR64SYSTEM\ControlSet002\Enum\Root\LEGACY_CHERIMOYASYSTEM\ControlSet002\services\05B93BAB-FAE5-44A8-9846-753385F00C07SYSTEM\ControlSet002\services\cherimoyaSYSTEM\ControlSet002\services\csrccSYSTEM\ControlSet002\services\DifkuCiabfSYSTEM\ControlSet002\services\shopperz UpdaterSYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\bsdpf64.sysSYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\bsdpr64.sysSYSTEM\CurrentControlSet\Control\SafeBoot\Network\bsdpf64.sysSYSTEM\CurrentControlSet\Control\SafeBoot\Network\bsdpr64.sysSYSTEM\CurrentControlSet\Enum\Root\LEGACY_BSDPF64SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BSDPR64SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CHERIMOYASYSTEM\CurrentControlSet\services\05B93BAB-FAE5-44A8-9846-753385F00C07SYSTEM\CurrentControlSet\services\cherimoyaSYSTEM\CurrentControlSet\services\csrccSYSTEM\CurrentControlSet\services\DifkuCiabfSYSTEM\CurrentControlSet\services\shopper-z UpdaterSYSTEM\CurrentControlSet\services\shopperz UpdaterSYSTEM\Setup\FirstBoot\Services\bsdriverHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{1735357F-0D26-4566-b78C-C847801AB3F0}{3C2C21F7-FDB6-4b10-B605-FA4A281E3016}_is1{5081D2D4-1637-404c-B74F-50526718257D}_is1{F0422270-2580-43FE-b53A-7F0BA1FB86E9}

Additional Information

The following directories were created:
%APPDATA%\Anyflixdum%APPDATA%\Asapg%APPDATA%\Ficjagmuv%APPDATA%\Fioxydo%APPDATA%\Haohpex%APPDATA%\Hejbuio%APPDATA%\Mafcaedbew%APPDATA%\Pywwiy%APPDATA%\Tueasjey%APPDATA%\Woehdovh%LOCALAPPDATA%\Tempfolder\ortmp%PROGRAMFILES%\Aiduwb%PROGRAMFILES%\AiduwbUn%PROGRAMFILES%\Ariqockatidge%PROGRAMFILES%\Atagary%PROGRAMFILES%\Busirekesp%PROGRAMFILES%\Ekeh%PROGRAMFILES%\Grgaentaneceing%PROGRAMFILES%\Holuge%PROGRAMFILES%\Kajajugt%PROGRAMFILES%\Qotayphust%PROGRAMFILES%\Shifipy%PROGRAMFILES%\VejqepopeupluvUn%PROGRAMFILES%\Yhid%PROGRAMFILES%\YhidUn%PROGRAMFILES%\Zohmaeffidwo%PROGRAMFILES%\shopper-z%PROGRAMFILES%\shopperz%PROGRAMFILES%\shopperz29072015%PROGRAMFILES(x86)%\Ariqockatidge%PROGRAMFILES(x86)%\Atagary%PROGRAMFILES(x86)%\Atequied%PROGRAMFILES(x86)%\Busirekesp%PROGRAMFILES(x86)%\Cholak%PROGRAMFILES(x86)%\Ekeh%PROGRAMFILES(x86)%\Grgaentaneceing%PROGRAMFILES(x86)%\Holuge%PROGRAMFILES(x86)%\Lmtyghodicult%PROGRAMFILES(x86)%\Qotayphust%PROGRAMFILES(x86)%\Shifipy%PROGRAMFILES(x86)%\Yhid%PROGRAMFILES(x86)%\YhidUn%PROGRAMFILES(x86)%\shopperz%PUBLIC%\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}%USERPROFILE%\AppData\LocalLow\Company\Product\1.0%USERPROFILE%\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}%USERPROFILE%\Application Data\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}%appdata%\GowvePitpagf
Loading...