Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

FEIYUE.EXE is Trojan Guntor.vynqz

$
0
0

Is the file FEIYUE.EXE located on your computer? Then your computer is infected.
We do suggest you should remove FEIYUE.EXE from your computer as soon as possible.
FEIYUE.EXE is Trojan/Backdoor.
Kill the process FEIYUE.EXE and remove FEIYUE.EXE from the Windows startup.

Malware Analysis of FEIYUE.EXE
Full path on a computer: %Program Files%\feiyue.exe

Detected by UnHackMe:

Item Name: [EXPL0RER]
Author:
Related File: %Program Files%\feiyue.exe
Type: Registry Run

Removal Results: Success
Number of reboot: 1

FEIYUE.EXE is known as:

Trojan.Guntor.vynqz, Guntior.A, Trojan.Jorik.Yoddos.agz, Packed.PECompact, TrojWare.Agent.XSIL, Trojan.Guntor.2, Trojan.Yoddos.dat (v), Mal.Jadtre-C, TrojanDropper.Jadtre.D, BScope.Trojan.Diple, a variant of Win32.Wapomi.AQ, Trojan.PSW.OnLineGames.4816

FEIYUE.EXE hash:

  • MD5: 50184ecf52055c518c9b57532070b62d
How to quickly detect FEIYUE.EXE presence?
Registry:
  • HKLM\Software\Microsoft\Windows\CurrentVersion\Run\[EXPL0RER]: “%Program Files%\feiyue.exe”
  • HKLM\System\CurrentControlSet\Services\6654481\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
  • HKLM\System\CurrentControlSet\Services\6654481\Type: 0×00000001
  • HKLM\System\CurrentControlSet\Services\6654481\Start: 0×00000003
  • HKLM\System\CurrentControlSet\Services\6654481\ErrorControl: 0×00000000
  • HKLM\System\CurrentControlSet\Services\6654481\ImagePath: “\??\%SysDir%\aw98fd4f41110″
  • HKLM\System\CurrentControlSet\Services\6654481\DisplayName: “6654481″
Files:
  • %Temp%\stinst.log
  • %Program Files%\feiyue.exe
  • %SysDir%\07CB0588.tmp
  • %SysDir%\3E530570.tmp
  • C:\ltev.exe


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>