Click on screenshot to zoom
Danger level 7
Type: Trojans

Other mutations known as:
Trojan.EyeStye.H , Trojan.EyeStye.N

Trojan.EyeStye

Trojan.EyeStye is a parasite which has a relatively high number of detections worldwide. It means that it can outsmart various antivirus programs and remain hidden in the system for a longer period of time. This Trojan has a few associations including Trojan.EyeStye.N and Trojan.EyeStye.H – they are different versions of the same computer threat. Due to the fact that this Trojan can lurk in the computer undetected for quite some time, it is recommended to keep your antivirus system up to date, and perform regular scans of your computer. It is also advisable to have more than one antispyware tool installed because that increases the security of your computer.

The fact that Trojan.EyeStye is so widespread also correlates to the evidence that the distribution system of this parasite is very well-developed. The carriers of the infection can spam email, browser hijackers and fake online malware scanners. But these are just a few of the examples, because there can be a lot more methods used by Trojan.EyeStye in order to slither into the system. In case of a fake online malware scanner (which is one of the most popular ways to get this infection), when the user lands in the hacked site, sometime he or she does not even need to click somewhere to initiate the download. The Trojan installation file can be downloaded automatically without the user’s knowledge or consent.

Sometimes the Trojan even pretends to be a useful program until it reveals its true face and starts harming the user and the computer. Trojan.EyeStye, actually, cannot spread on its own accord. It has to be downloaded by the user. And the number of malicious actions it can perform in the infected computer can also depend on the attacker’s choice. The point is that Trojan.EyeStye allows a remote access to the infected computer, and a hacker can enter the system in question over the Internet. Trojans like this one are used to spy on the users and then steal important data via keylogging. The user does not even notice when his logins and banking passwords are stolen from him.

Since it is hard to tell exactly when one gets infected by Trojan.EyeStye, if the user senses something wrong, it is recommended to check the Windows Task Manager for the list of processes associated with this Trojan. Some of the processes include Portwexexe.exe and diskheckrt.exe. These processes are classified as cloaked malware and it means that they are very good at avoiding being detected by the computer security programs. Also, the process flashplay.exe is malicious software which can download various types of malware onto the infected computer. That is so, because it can communicate with other computer systems over the network. There are also processes which play on the similar sounding of the names. Say, wmplayer.exe is a legitimate Windows process, associated with the Windows Media Player. However, Trojan.EyeStye comes with a process called wmplay.exe. This process obviously tries to hide itself in order to prolong its stay in the computer not only by changing the register entries, but also by imitating the name of a genuine process.

Of course it is possible get rid of Trojan.EyeStye and all of its components manually. The user needs to locate them in the system and delete them. However, that requires higher than average knowledge in computing, and if the user is not too sure how his computer’s system it is best to leave the removing of Trojan.EyeStye to an automatic antimalware program. That way the parasite will be deleted successfully and the user will avoid making unnecessary changes to the system.

Download Spyware Removal Tool to Remove* Trojan.EyeStye
  • Quick & tested solution for Trojan.EyeStye removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Trojan.EyeStye

Files associated with Trojan.EyeStye infection:

SpyEye.exe
zzzzzzzzzz.exe
nvsvc32.exe
malacuxatx.exe
mscrtservc.exe
wmplay.exe
spy.qwas.exe
memcachexx.exe
svest.exe
zzzzheckrt.exe
mydnswatch.exe
RestorPoint.exe
cocacolais.exe
cleansweep.exe
CD16509865D.exe
B6232F3A2B5.exe
CD165098B37.exe
CD1650988AA.exe
C08436D155F.exe
B8DEA5BB335.exe
B8DEA5BB1C0.exe
B62B2F3ACDC.exe
B6232F3AF32.exe
B6232F3AEC6.exe
B6232F3ABBD.exe
B6232F3AA3D.exe
B6232F3A9D6.exe
B6232F3A93A.exe
B6232F3A75C.exe
B6232F3A3F3.exe
B6232F3A228.exe
B6232F3A1CA.exe
9CDEA5FB956.exe
9A0D2F91FE8.exe
9A0D2F919F6.exe
9A0D2F9189D.exe
9A0D2F9185C.exe
9A0D2F9107A.exe
9A0D2F91044.exe
9A0B33B117F.exe
8948CD57D2C.exe
8948CD57335.exe
7868B19A03C.exe
64171B600D1.exe
50BE4DF0B35.exe
50BE4DF0207.exe
2608DF01BB4.exe
pijgfiudghd.exe
mscrtservc.exe
dyfhiushduh.exe
B6232F3A6D5.exe
2811CB89DBB.exe
CD165098AE8.exe
YouMeetWeWo.exe
systemsvc.exe
sisale.bin.exe
rterk.bin.exe
GEROINSSVSE.exe
FC78BA65BBF.exe
FC78BA65A3C.exe
F12D04846DF.exe
eyw5.bin.exe
EB013E7D746.exe
E735495FB28.exe
E735495F104.exe
E70F77091D5.exe
E11249812C6.exe
dialcfg.bin.exe
D60D329147E.exe
D5B0B7659BB.exe
D232F5B6B11.exe
D232F5B629C.exe
chererasras.exe
CD165098D36.exe
CD165098A23.exe
CD165098555.exe
CA0A4982BC7.exe
CA0A4982782.exe
C08436D15C6.exe
B8DEA5BBE28.exe
B8DEA5BBAA7.exe
B8DEA5BB9B6.exe
B8DEA5BB7D7.exe
B8DEA5BB654.exe
B8DEA5BB626.exe
B8DEA5BB5CF.exe
B6232F3AFE2.exe
B6232F3AF1A.exe
B6232F3AEA1.exe
B6232F3AE33.exe
B6232F3ADD1.exe
B6232F3AD43.exe
B6232F3AD26.exe
B6232F3ACD5.exe
B6232F3ACBF.exe
B6232F3AC9D.exe
B6232F3AC3D.exe
B6232F3AC32.exe
B6232F3AC17.exe
B6232F3AC10.exe
B6232F3ABD7.exe
B6232F3ABD2.exe
B6232F3AB3F.exe
B6232F3AB26.exe
B6232F3AB13.exe
B6232F3AACC.exe
B6232F3A9B1.exe
B6232F3A9A3.exe
B6232F3A9A1.exe
B6232F3A989.exe
B6232F3A979.exe
B6232F3A8A7.exe
B6232F3A882.exe
B6232F3A81E.exe
B6232F3A7A6.exe
B6232F3A792.exe
B6232F3A6B5.exe
B6232F3A6B4.exe
B6232F3A5B9.exe
B6232F3A578.exe
B6232F3A559.exe
B6232F3A540.exe
B6232F3A4DE.exe
B6232F3A446.exe
B6232F3A43F.exe
B6232F3A3A4.exe
B6232F3A2D6.exe
B6232F3A2BC.exe
B6232F3A25C.exe
B6232F3A24A.exe
B6232F3A1E8.exe
B6232F3A1AF.exe
B6232F3A159.exe
B6232F3A123.exe
B6232F3A059.exe
B6232F3A04C.exe
B6232F3A036.exe
B6232F3A02E.exe
AVG.bin.exe
alogn0.bin.exe
AE947CD1CD6.exe
A96C465EF39.exe
A96C465E941.exe
A96C465E5B2.exe
A7350D82E11.exe
A7350D82ACB.exe
A639377C051.exe
A630718CE11.exe
A630718CAD5.exe
A630718C792.exe
A0317581FB4.exe
A0317581F6C.exe
A0317581B6E.exe
A03175819DF.exe
9E7D30721B5.exe
9E707AEFE3D.exe
9A0D2F917EB.exe
9A0D2F913AA.exe
9A0B33B1B13.exe
9A052F91C56.exe
8BF491C5C2D.exe
834B0E45663.exe
831868815C6.exe
810F3B42AAB.exe
80357BFA844.exe
7E402E93DE0.exe
77176FB41B5.exe
701BE486C5E.exe
6F52FD9A3BE.exe
6DFBBA77264.exe
4DD27453B8D.exe
4D525EC18EC.exe
44190F8F690.exe
353F13998DD.exe
2C3F67F936C.exe
28ED2723DE0.exe
2811CB89523.exe
217FA966EBA.exe
217FA9664CE.exe
0EBD6955035.exe
0E4736D004C.exe
03576683DCD.exe
02126517F4F.exe
02126517B09.exe
021265172CB.exe
queryscan133.exe
BTStacPgn.exe
%USERPROFILE%/AppWm/cevrgmb.exe
e-cards.exe
SpyEye.exe
cocacolais.exe
usxxxxxxxx.exe
dufsjlifhkd.exe
7bHY3.com
SYSINV32.exe
spuninst.exe
735FC311.exe
SynNglp.exe
calc[1].exe
zzzzheckrt.exe
windowseep.exe
sysapp.exe
svest.exe
spy.qwas.exe
skhfushjflw.exe
Ricycle.Bin.exe
RestorPoint.exe
recyclebin.exe
Recycle.Bin.exe
mydnswatch.exe
moonxxxxxx.exe
malacuxatx.exe
fsdfkl3.Bin.exe
flashplay.exe
winntse.bin.exe
zzzzzzzzzz.exe
wmplay.exe
diskheckrt.exe
visfree.exe
syscheckrt.exe
sdjfdskpogf.exe
osidfjklsdw.exe
$Recycle$.exe
nvsvc32.exe
portwexexe.exe
cleansweep.exe
5ytw.exe
portwexexe.exe
sdjfdskpogf.exe
windowseep.exe
recyclebin.exe
flashplay.exe
Recycle.Bin.exe
5ytw.exe
syscheckrt.exe
fsdfkl3.Bin.exe
Ricycle.Bin.exe
moonxxxxxx.exe
osidfjklsdw.exe
dufsjlifhkd.exe
dyfhiushduh.exe
diskheckrt.exe
$Recycle$.exe
skhfushjflw.exe
pijgfiudghd.exe
visfree.exe
sysapp.exe

Trojan.EyeStye processes to kill:

skhfushjflw.exe
flashplay.exe
svest.exe
Ricycle.Bin.exe
pijgfiudghd.exe
nvsvc32.exe
recyclebin.exe
fsdfkl3.Bin.exe
RestorPoint.exe
windowseep.exe
zzzzheckrt.exe
memcachexx.exe
mydnswatch.exe
wmplay.exe
$Recycle$.exe
zzzzzzzzzz.exe
osidfjklsdw.exe
moonxxxxxx.exe
cocacolais.exe
dufsjlifhkd.exe
CD16509865D.exe
B6232F3A2B5.exe
CD165098B37.exe
CD1650988AA.exe
C08436D155F.exe
B8DEA5BB335.exe
B8DEA5BB1C0.exe
B62B2F3ACDC.exe
B6232F3AF32.exe
B6232F3AEC6.exe
B6232F3ABBD.exe
B6232F3AA3D.exe
B6232F3A9D6.exe
B6232F3A93A.exe
B6232F3A75C.exe
B6232F3A3F3.exe
B6232F3A228.exe
B6232F3A1CA.exe
9CDEA5FB956.exe
9A0D2F91FE8.exe
9A0D2F919F6.exe
9A0D2F9189D.exe
9A0D2F9185C.exe
9A0D2F9107A.exe
9A0D2F91044.exe
9A0B33B117F.exe
8948CD57D2C.exe
8948CD57335.exe
7868B19A03C.exe
64171B600D1.exe
50BE4DF0B35.exe
50BE4DF0207.exe
2608DF01BB4.exe
pijgfiudghd.exe
mscrtservc.exe
dyfhiushduh.exe
B6232F3A6D5.exe
2811CB89DBB.exe
CD165098AE8.exe
YouMeetWeWo.exe
systemsvc.exe
sisale.bin.exe
rterk.bin.exe
GEROINSSVSE.exe
FC78BA65BBF.exe
FC78BA65A3C.exe
F12D04846DF.exe
eyw5.bin.exe
EB013E7D746.exe
E735495FB28.exe
E735495F104.exe
E70F77091D5.exe
E11249812C6.exe
dialcfg.bin.exe
D60D329147E.exe
D5B0B7659BB.exe
D232F5B6B11.exe
D232F5B629C.exe
chererasras.exe
CD165098D36.exe
CD165098A23.exe
CD165098555.exe
CA0A4982BC7.exe
CA0A4982782.exe
C08436D15C6.exe
B8DEA5BBE28.exe
B8DEA5BBAA7.exe
B8DEA5BB9B6.exe
B8DEA5BB7D7.exe
B8DEA5BB654.exe
B8DEA5BB626.exe
B8DEA5BB5CF.exe
B6232F3AFE2.exe
B6232F3AF1A.exe
B6232F3AEA1.exe
B6232F3AE33.exe
B6232F3ADD1.exe
B6232F3AD43.exe
B6232F3AD26.exe
B6232F3ACD5.exe
B6232F3ACBF.exe
B6232F3AC9D.exe
B6232F3AC3D.exe
B6232F3AC32.exe
B6232F3AC17.exe
B6232F3AC10.exe
B6232F3ABD7.exe
B6232F3ABD2.exe
B6232F3AB3F.exe
B6232F3AB26.exe
B6232F3AB13.exe
B6232F3AACC.exe
B6232F3A9B1.exe
B6232F3A9A3.exe
B6232F3A9A1.exe
B6232F3A989.exe
B6232F3A979.exe
B6232F3A8A7.exe
B6232F3A882.exe
B6232F3A81E.exe
B6232F3A7A6.exe
B6232F3A792.exe
B6232F3A6B5.exe
B6232F3A6B4.exe
B6232F3A5B9.exe
B6232F3A578.exe
B6232F3A559.exe
B6232F3A540.exe
B6232F3A4DE.exe
B6232F3A446.exe
B6232F3A43F.exe
B6232F3A3A4.exe
B6232F3A2D6.exe
B6232F3A2BC.exe
B6232F3A25C.exe
B6232F3A24A.exe
B6232F3A1E8.exe
B6232F3A1AF.exe
B6232F3A159.exe
B6232F3A123.exe
B6232F3A059.exe
B6232F3A04C.exe
B6232F3A036.exe
B6232F3A02E.exe
AVG.bin.exe
alogn0.bin.exe
AE947CD1CD6.exe
A96C465EF39.exe
A96C465E941.exe
A96C465E5B2.exe
A7350D82E11.exe
A7350D82ACB.exe
A639377C051.exe
A630718CE11.exe
A630718CAD5.exe
A630718C792.exe
A0317581FB4.exe
A0317581F6C.exe
A0317581B6E.exe
A03175819DF.exe
9E7D30721B5.exe
9E707AEFE3D.exe
9A0D2F917EB.exe
9A0D2F913AA.exe
9A0B33B1B13.exe
9A052F91C56.exe
8BF491C5C2D.exe
834B0E45663.exe
831868815C6.exe
810F3B42AAB.exe
80357BFA844.exe
7E402E93DE0.exe
77176FB41B5.exe
701BE486C5E.exe
6F52FD9A3BE.exe
6DFBBA77264.exe
4DD27453B8D.exe
4D525EC18EC.exe
44190F8F690.exe
353F13998DD.exe
2C3F67F936C.exe
28ED2723DE0.exe
2811CB89523.exe
217FA966EBA.exe
217FA9664CE.exe
0EBD6955035.exe
0E4736D004C.exe
03576683DCD.exe
02126517F4F.exe
02126517B09.exe
021265172CB.exe
queryscan133.exe
BTStacPgn.exe
%USERPROFILE%/AppWm/cevrgmb.exe
e-cards.exe
SpyEye.exe
cocacolais.exe
usxxxxxxxx.exe
dufsjlifhkd.exe
SYSINV32.exe
spuninst.exe
735FC311.exe
SynNglp.exe
calc[1].exe
zzzzzzzzzz.exe
zzzzheckrt.exe
wmplay.exe
wmplay.exe
windowseep.exe
visfree.exe
syscheckrt.exe
sysapp.exe
svest.exe
spy.qwas.exe
skhfushjflw.exe
sdjfdskpogf.exe
Ricycle.Bin.exe
RestorPoint.exe
RestorPoint.exe
recyclebin.exe
Recycle.Bin.exe
Recycle.Bin.exe
Recycle.Bin.exe
Recycle.Bin.exe
Recycle.Bin.exe
Recycle.Bin.exe
Recycle.Bin.exe
Recycle.Bin.exe
portwexexe.exe
portwexexe.exe
portwexexe.exe
osidfjklsdw.exe
nvsvc32.exe
nvsvc32.exe
mydnswatch.exe
mydnswatch.exe
moonxxxxxx.exe
malacuxatx.exe
fsdfkl3.Bin.exe
flashplay.exe
diskheckrt.exe
diskheckrt.exe
diskheckrt.exe
cleansweep.exe
cleansweep.exe
5ytw.exe
$Recycle$.exe
$Recycle$.exe
winntse.bin.exe
zzzzzzzzzz.exe
wmplay.exe
diskheckrt.exe
visfree.exe
syscheckrt.exe
sdjfdskpogf.exe
portwexexe.exe
portwexexe.exe
osidfjklsdw.exe
nvsvc32.exe
$Recycle$.exe
nvsvc32.exe
portwexexe.exe
cleansweep.exe
5ytw.exe
sysapp.exe
malacuxatx.exe
Recycle.Bin.exe
SpyEye.exe
dyfhiushduh.exe
mscrtservc.exe
cleansweep.exe
5ytw.exe
diskheckrt.exe
spy.qwas.exe
sdjfdskpogf.exe
visfree.exe
syscheckrt.exe
portwexexe.exe
Disclaimer

Comments

  1. Felipe ! Oct 26, 2011

    Thanks ! Gracias ! mucha ayuda !

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.