Is the file FEIYUE.EXE located on your computer? Then your computer is infected.
We do suggest you should remove FEIYUE.EXE from your computer as soon as possible.
FEIYUE.EXE is Trojan/Backdoor.
Kill the process FEIYUE.EXE and remove FEIYUE.EXE from the Windows startup.
Malware Analysis of FEIYUE.EXE
Full path on a computer: %Program Files%\feiyue.exe
Detected by UnHackMe:
Item Name: [EXPL0RER]
Author:
Related File: %Program Files%\feiyue.exe
Type: Registry Run
Removal Results: Success
Number of reboot: 1
FEIYUE.EXE is known as:
Trojan.Guntor.vynqz, Guntior.A, Trojan.Jorik.Yoddos.agz, Packed.PECompact, TrojWare.Agent.XSIL, Trojan.Guntor.2, Trojan.Yoddos.dat (v), Mal.Jadtre-C, TrojanDropper.Jadtre.D, BScope.Trojan.Diple, a variant of Win32.Wapomi.AQ, Trojan.PSW.OnLineGames.4816
FEIYUE.EXE hash:
- MD5: 50184ecf52055c518c9b57532070b62d
How to quickly detect FEIYUE.EXE presence?
Registry:
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\[EXPL0RER]: “%Program Files%\feiyue.exe”
- HKLM\System\CurrentControlSet\Services\6654481\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
- HKLM\System\CurrentControlSet\Services\6654481\Type: 0×00000001
- HKLM\System\CurrentControlSet\Services\6654481\Start: 0×00000003
- HKLM\System\CurrentControlSet\Services\6654481\ErrorControl: 0×00000000
- HKLM\System\CurrentControlSet\Services\6654481\ImagePath: “\??\%SysDir%\aw98fd4f41110″
- HKLM\System\CurrentControlSet\Services\6654481\DisplayName: “6654481″
Files:
- %Temp%\stinst.log
- %Program Files%\feiyue.exe
- %SysDir%\07CB0588.tmp
- %SysDir%\3E530570.tmp
- C:\ltev.exe