The file GOLAYA-PHOTO.EXE is identified as the Trojan Program that is used for stealing bank information and users passwords.
To delete GOLAYA-PHOTO.EXE we suggest you should use UnHackMe:
http://www.unhackme.com
Malware Analysis of GOLAYA-PHOTO.EXE
Full path on a computer: %TEMP%\GOLAYA-PHOTO.EXE
Detected by UnHackMe:
GOLAYA-PHOTO.EXE
Default location: %TEMP%\GOLAYA-PHOTO.EXE
Removal Results: Success
Number of reboot: 1
GOLAYA-PHOTO.EXE is known as:
Trojan Qhost
GOLAYA-PHOTO.EXE hash:
-
MD5: 25ABD8DD9A991F74998887D7E12AB271
How to quickly detect GOLAYA-PHOTO.EXE presence?
Files:
- %TEMP%\$INST\2.TMP
- %TEMP%\GOLAYA-PHOTO.EXE
- %SYSTEM%\DRIVERS\ETC\H?STS
- %PROGRAMFILES%\POWER INVERTERS, RADAR\TOURISM WHISTLER OFFERS COMPREHENSIVE\ALL.VBS