We checked up the file QINGYUGE.EXE and found it hazardous.
The file QINGYUGE.EXE must be deleted from the system immediately.
Kill the process QINGYUGE.EXE and remove QINGYUGE.EXE from the Windows startup.
Malware Analysis of QINGYUGE.EXE
Full path on a computer: %APPDATA%\QINGYUGE\QINGYUGE 1.2.0\INSTALL\01CC0D0\QINGYUGE.EXE
Detected by UnHackMe:
QINGYUGE.EXE
Default location: %APPDATA%\QINGYUGE\QINGYUGE 1.2.0\INSTALL\01CC0D0\QINGYUGE.EXE
Removal Results: Success
Number of reboot: 1
QINGYUGE.EXE is known as:
Trojan Downloader
How to quickly detect QINGYUGE.EXE presence?
Files:
- %SYSTEMDRIVE%\QINGYUGE\QINGYUGE.EXE
- %SYSTEMDRIVE%\QINGYUGE\CONFIG.BOB
- %SYSTEMDRIVE%\CONFIG.MSI\617B4.RBS
- %SYSTEMDRIVE%\SYSTEM VOLUME INFORMATION\_RESTORE{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\SNAPSHOT\REPOSITORY\FS\INDEX.BTR
- %APPDATA%\QINGYUGE\QINGYUGE 1.2.0\INSTALL\01CC0D0\QINGYUGE.EXE