Ads by Hades. Removal solution

Ads by Hades will truly give you a headache. It is definitely easier to prevent the installation of this adware ahead of time then to look for the ways of its removal after the attack of this application already took place. Hades adware is generally installed into PCs through being bundled by default with many other free applications. In this tutorial we will help you to understand how to get rid of this disgusting program from your system.

Hades Ads

Hades adware is capable to attack practically all major browsers today, including Google Chrome, Mozilla Firefox and Internet Explorer. You may notice that this program introduces its own add-on (extension) into all these browsers. Plus, you may see its name to be shown in the list of legally installed applications of your system.

The purpose of this program is to display various ads through your browser to make you observe them or click on them. This will bring profit to those who stand behind this application. We strongly recommend you not to click on these Ads by Hades, no matter how tricky they are in their attempts to make you do so.

Hades adware program is actively bundled with many other free applications today. You need to make sure you know what exactly you’re suggested to install into your system in addition to the main application of your choice. If you read about this Hades of any other unwanted application suggested to be installed into your system by default, make sure you switch to the advanced or custom installation mode. This is the place where you may uncheck all these additional applications from being installed into your system by default.

Users who actually fail to be duly attentive during freeware installation may end up installing Hades and a lot of other absolutely not necessary program into their PCs. This adware will considerably slow down the performance of your PC and make your browsing as a truly very annoying experience. To sum up, we recommend you to remove this junk application from your system by carefully following the uninstall tutorial provided in the rest of this article. Again, if you require more help, please contact us without hesitation.

Download Combo Cleaner

Anti-malware tool necessary to eliminate Hades automatically.

Download GridinSoft Trojan Killer

Detailed automatic removal instructions:

  • Download GridinSoft Trojan Killer via the download button (above).
  • Install the application and scan your computer with it.
  • At the end of scan click “Apply” to remove all infections related to this adware:
  • Apply scan results by Trojan Killer

  • Important! It is also very important that you reset your browsers using GridinSoft Trojan Killer after you delete this particular adware. Shut down all your available browsers right now.
  • In GridinSoft Trojan Killer click on “Tools” tab and select “Reset browser settings“:
  • Tool to reset browser settings

  • Select which particular browsers you would like to be reset and choose the reset options:
  • Options to reset browsers

  • Finally, Click on “Reset” button.
  • You will receive the confirmation windows about browser settings reset successfully.
  • Reboot your system now.

Video explaining how to reset your browser using GridinSoft Trojan Killer:

Manual (free) instructions to get rid of Hades.

Step 1. Uninstalling Hades from the Control Panel of your computer.

  1. Make sure that all your browsers infected with Hades are shut down (closed).
  2. In Windows XP, Vista and 7 click on “Start” and go to the “Control Panel“:
  3. Accessing the Control Panel in Windows XP, Vista and 7 versions

  4. To access the Control Panel in Windows 8 or 8.1, move the PC mouse next to the left-bottom hot corner of your Windows 8 or 8.1 screen, then right-click on it:
  5. How to access the Control Panel in Windows 8 and 8.1

  6. In Windows XP click on “Add or remove programs“:
  7. Add or remove programs in Windows XP

  8. In Windows Vista, 7, 8 and 8.1 click on “Uninstall a program“:
  9. Uninstall a program in Windows Vista, 7, 8 and 8.1

  10. Uninstall Hades adware program from your system. To do it, in Windows XP click “Remove” button related to it. In Windows Vista, 7, 8 and 8.1 right-click on Hades program with the computer mouse and click on “Uninstall / Change“.
  11. Step 2. Removing the adware from the list of add-ons and extensions of your browser.

    In addition to removal of any suspicious adware programs from the Control Panel of your PC as explained above, you also need to remove this adware from the add-ons or extensions of your browser. Please follow this guide for managing browser add-ons and extensions for more detailed information. Remove any items related to this particular adware and other unwanted applications installed on your PC.

Technical information about Hades adware:

Added files:

%ProgramFiles%\Hades\
%ProgramFiles%\Hades\HadesUninstaller.exe
%ProgramFiles%\Hades\uninstall.exe
%ProgramFiles%\Smwyyntm1ndi1zdz\
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfs15E7.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfs37BE.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfs381D.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfs381E.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfs8162.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfs9AF9.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsA1A2.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsA348.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsA6D4.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsA7A0.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsA7A1.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsAA42.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsB26.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsBC05.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsBC90.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsDB27.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsE48E.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsE48F.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsE490.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsEB66.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsEBE4.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsF6B3.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsF6B4.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\mfsF6B5.tmp
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-a.analytics.yahoo.com-c4da682f90194494cf46d5c2997046d51122345c#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-a.analytics.yahoo.com-c4da682f90194494cf46d5c2997046d51122345c#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-ad.doubleclick.net-40b9e046a63335967dfa898af37a7c2d5ae92c6f#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-ad.doubleclick.net-40b9e046a63335967dfa898af37a7c2d5ae92c6f#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-adr-g3-1.vindicosuite.com-8ef1fd38e48be9a76941759ca73743a88a41a715#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-adr-g3-1.vindicosuite.com-8ef1fd38e48be9a76941759ca73743a88a41a715#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-adsrvmedia.adk2.co-4bfc3da8c4d6274f4ca3d0b835a582e04ec99997#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-adsrvmedia.adk2.co-4bfc3da8c4d6274f4ca3d0b835a582e04ec99997#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-b.scorecardresearch.com-f01a81f9c6c0a1ffb26b477fa38145ce428a4ff9#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-b.scorecardresearch.com-f01a81f9c6c0a1ffb26b477fa38145ce428a4ff9#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-cdn.vindicosuite.com-320f24ae52f5691ba6e6199d847a1fd75be79b86#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-cdn.vindicosuite.com-320f24ae52f5691ba6e6199d847a1fd75be79b86#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-choices.truste.com-6a02d86710971ca3082dfedaa58e29932d6828c5#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-choices.truste.com-6a02d86710971ca3082dfedaa58e29932d6828c5#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-geo.query.yahoo.com-e460e390a2ca7fc5df0590aa1f4f31fa39773fb8#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-geo.query.yahoo.com-e460e390a2ca7fc5df0590aa1f4f31fa39773fb8#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-graph.facebook.com-a4fb65f8a157fe0dc017c1b55162633a1873a0b4#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-graph.facebook.com-a4fb65f8a157fe0dc017c1b55162633a1873a0b4#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-inimage.tr553.com-2206b4547fde5ced5fff10445216b3ccba5d000f#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-inimage.tr553.com-2206b4547fde5ced5fff10445216b3ccba5d000f#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-login.live.com-d4186b6e6d826a53c9a62ef2c0cd1b45c0e7e6c4#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-login.live.com-d4186b6e6d826a53c9a62ef2c0cd1b45c0e7e6c4#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-ny-aaa.net-b4b57457ac0412ea3a6fece4c20e107c1ce95977#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-ny-aaa.net-b4b57457ac0412ea3a6fece4c20e107c1ce95977#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-pixel.adsafeprotected.com-874aaf9aebbd586fe09951781dca43bdd748e1d5#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-pixel.adsafeprotected.com-874aaf9aebbd586fe09951781dca43bdd748e1d5#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-pixel.everesttech.net-e90a182884ad4e7e532b6aa759fbf9d1b05d742d#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-pixel.everesttech.net-e90a182884ad4e7e532b6aa759fbf9d1b05d742d#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-ppd.clrstm.com-4e5dfddb97b3bc159c343700811dcb814bcd266b#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-ppd.clrstm.com-4e5dfddb97b3bc159c343700811dcb814bcd266b#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-rtd.tubemogul.com-777e73e679eb7b1718ea35730aaf327ef01f9289#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-rtd.tubemogul.com-777e73e679eb7b1718ea35730aaf327ef01f9289#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-s-static.ak.facebook.com-23b719b5a410d3ac80aeb5f4a25adf4cc827f708#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-s-static.ak.facebook.com-23b719b5a410d3ac80aeb5f4a25adf4cc827f708#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-s.yimg.com-927385df9579c9d9130942f4f38ac3cf80a2017b#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-s.yimg.com-927385df9579c9d9130942f4f38ac3cf80a2017b#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-s3-eu-west-1.amazonaws.com-8c6376dc87fe68f22dab490c35ab12469b7a8116#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-s3-eu-west-1.amazonaws.com-8c6376dc87fe68f22dab490c35ab12469b7a8116#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-savecdn.com-fc69fb2bad8b341f1286e439aa4f777b53467d23#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-savecdn.com-fc69fb2bad8b341f1286e439aa4f777b53467d23#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-sc.iasds01.com-223a8c90f0c13cf6aea2f3a1f5506b13c4e3fadf#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-sc.iasds01.com-223a8c90f0c13cf6aea2f3a1f5506b13c4e3fadf#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-sdk.vindicosuite.com-320f24ae52f5691ba6e6199d847a1fd75be79b86#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-sdk.vindicosuite.com-320f24ae52f5691ba6e6199d847a1fd75be79b86#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-secure.adnxs.com-50f27e06a7ddfe11b8f563d42150626c9a320283#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-secure.adnxs.com-50f27e06a7ddfe11b8f563d42150626c9a320283#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-securepubads.g.doubleclick.net-295dbc3dd052a751ab29810476cdec630d9776bc#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-securepubads.g.doubleclick.net-295dbc3dd052a751ab29810476cdec630d9776bc#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-spc--cebhhhpgffbhedbeichhbdje--vast2as3.telemetryverification.net-ddd6995a52695c5cca9f308c053939a761c5ab7c#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-spc--cebhhhpgffbhedbeichhbdje--vast2as3.telemetryverification.net-ddd6995a52695c5cca9f308c053939a761c5ab7c#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-static.adsafeprotected.com-874aaf9aebbd586fe09951781dca43bdd748e1d5#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-static.adsafeprotected.com-874aaf9aebbd586fe09951781dca43bdd748e1d5#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-syndication.streamads.yahoo.com-03da423a320861974f1061f2cd362f512e1cb9f7#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-syndication.streamads.yahoo.com-03da423a320861974f1061f2cd362f512e1cb9f7#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-ty.ts.vindicosuite.com-203242df74056b6da1eaa85f082df9d49ddaca97#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-ty.ts.vindicosuite.com-203242df74056b6da1eaa85f082df9d49ddaca97#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-urs.microsoft.com-3935f4bbdd59a690507b666351c61b43a64c1ed8#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-urs.microsoft.com-3935f4bbdd59a690507b666351c61b43a64c1ed8#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-www.facebook.com-a4fb65f8a157fe0dc017c1b55162633a1873a0b4#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-www.facebook.com-a4fb65f8a157fe0dc017c1b55162633a1873a0b4#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-www.google.com-4e73d6b5900f60240c6153be8c5fe4eff7f3ad54#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-www.google.com-4e73d6b5900f60240c6153be8c5fe4eff7f3ad54#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-www.msn.com-78d0f042a3ded4f9137f40cd94b8763833d2ebb0#child.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA-www.msn.com-78d0f042a3ded4f9137f40cd94b8763833d2ebb0#child.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\Hades CA.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\test.cer
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz\SSL\test.pvk
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz.exe
%ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz.log
%ProgramFiles%\Smwyyntm1ndi1zdz\nss\
%ProgramFiles%\Smwyyntm1ndi1zdz\nss\certutil.exe
%ProgramFiles%\Smwyyntm1ndi1zdz\nss\mozcrt19.dll
%ProgramFiles%\Smwyyntm1ndi1zdz\nss\nspr4.dll
%ProgramFiles%\Smwyyntm1ndi1zdz\nss\nss3.dll
%ProgramFiles%\Smwyyntm1ndi1zdz\nss\plc4.dll
%ProgramFiles%\Smwyyntm1ndi1zdz\nss\plds4.dll
%ProgramFiles%\Smwyyntm1ndi1zdz\nss\smime3.dll
%ProgramFiles%\Smwyyntm1ndi1zdz\nss\softokn3.dll
%ProgramFiles%\Smwyyntm1ndi1zdz\settings.txt
%ProgramFiles%\Umtayyznhndq1ntz\
%ProgramFiles%\Umtayyznhndq1ntz\mtuyntm5ndy1yjy.exe
%ProgramFiles%\Umtayyznhndq1ntz\mtuyntm5ndy1yjy.log
%ProgramFiles%\Umtayyznhndq1ntz\mwmyzjmzngu1mdy.dat
%ProgramFiles%\Umtayyznhndq1ntz\mwmyzjmzngu1mdy.exe
%ProgramFiles%\Umtayyznhndq1ntz\mwmyzjmzngu1mdy.log
%System%\drivers\nmjim2z2zhm1bgz.sys

Added registry entries:

HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\mwyyntm1ndi1zdz %ProgramFiles%\Smwyyntm1ndi1zdz\nmjim2z2zhm1bgz.exe
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\CrashMon "%ProgramFiles%\Umtayyznhndq1ntz\mtuyntm5ndy1yjy.exe" "UniversalUpdater" "http://log.data-url.com/crash/"
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Hades
HKLM\SOFTWARE\Wow6432Node\Hades
HKLM\SOFTWARE\Wow6432Node\Universal
HKLM\SYSTEM\CurrentControlSet\services\nmjim2z2zhm1bgz
HKLM\SYSTEM\CurrentControlSet\services\UniversalUpdater