Remove QYCLIENT.EXE malware

QYCLIENT.EXE Malware Removal Guide

Manual removal instructions:

Antivirus Report of QYCLIENT.EXE:
QYCLIENT.EXE Malware
QYCLIENT.EXEDangerous
QYCLIENT.EXEHigh Risk
qyclient.exe
Full path on a computer: %PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE
Autostart registry keys:
HKLM\Software\Classes\Applications\QyClient.exe
HKLM\Software\Classes\Applications\QyClient.exe\SupportedTypes
HKLM\Software\Classes\Applications\QyClient.exe\SupportedTypes\.pfv: ""
HKLM\Software\Classes\Applications\QyClient.exe\SupportedTypes\.qsv: ""
HKLM\SOFTWARE\CLASSES\CLSID\{CF3CDEFB-31BE-43AE-B064-B9C62C883259}\SHELL\OPEN\COMMAND\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE WEB_STARTUP_TRAY"
HKLM\SOFTWARE\CLASSES\CLSID\{CF3CDEFB-31BE-43AE-B064-B9C62C883259}\DEFAULTICON\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE,0"
HKLM\SOFTWARE\CLASSES\.PGF\DEFAULTICON\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE,-317"
HKLM\SOFTWARE\CLASSES\.PMV\DEFAULTICON\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE,-148"
HKLM\SOFTWARE\CLASSES\MAGNET2\SHELL\OPEN\COMMAND\: ""%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE" -PPSTREAM "%1""
HKLM\SOFTWARE\CLASSES\MAGNET2\DEFAULTICON\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE,-0"
HKLM\SOFTWARE\CLASSES\PPS\SHELL\OPEN\COMMAND\: ""%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE" -PPSTREAM "%1""
HKLM\SOFTWARE\CLASSES\PPS\DEFAULTICON\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE,-0"
HKLM\SOFTWARE\CLASSES\PPSRUN\SHELL\OPEN\COMMAND\: ""%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE" -PPSTREAM "%1""
HKLM\SOFTWARE\CLASSES\PPSRUN\DEFAULTICON\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE,-0"
HKLM\SOFTWARE\CLASSES\PPSTREAM\SHELL\OPEN\COMMAND\: ""%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE" -PPSTREAM "%1""
HKLM\SOFTWARE\CLASSES\PPSTREAM\DEFAULTICON\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE,-0"
HKLM\SOFTWARE\CLASSES\PPS_PFV\SHELL\OPEN\COMMAND\: ""%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE" -PPSTREAM "%1""
HKLM\SOFTWARE\CLASSES\PPS_PFV\DEFAULTICON\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE,-107"
HKLM\SOFTWARE\CLASSES\PPS_QSV\SHELL\OPEN\COMMAND\: ""%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE" -PPSTREAM "%1""
HKLM\SOFTWARE\CLASSES\QIPS\SHELL\OPEN\COMMAND\: ""%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE" -PPSTREAM "%1""
HKLM\SOFTWARE\CLASSES\QIPS\DEFAULTICON\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE,-0"
HKLM\SOFTWARE\CLASSES\QISU\SHELL\OPEN\COMMAND\: ""%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE" -PPSTREAM "%1""
HKLM\SOFTWARE\CLASSES\QISU\DEFAULTICON\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE,-0"
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E6A8DA1-1731-465B-B036-B9E16EF26CAC}\AppName: "QyClient.exe"
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAC94FEE-45B4-4FD4-9EEA-D8978EC96C6E}\AppName: "QyClient.exe"
HKLM\Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\QyClient.exe: 0x00002AF8
HKLM\Software\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_GPU_RENDERING\QyClient.exe: 0x00000001
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\PPSTREAM.EXE\: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE"
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PPSTREAM\DISPLAYICON: "%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE"
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES\{CB076E15-D1C3-43D8-A01D-7066F7FB0722}: "V2.10|ACTION=ALLOW|ACTIVE=TRUE|DIR=IN|APP=%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE|NAME=????????|DESC=%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE|"
Related Files:
%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYAPPPLUGIN\WASABI\INSTALL.INI
%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYAPPPLUGIN\WASABI\WASABI.DLL.XML.STRATEGY
%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYCLIENT.EXE
%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYDLNA.DLL
%PROGRAM FILES%\IQIYI VIDEO\LSTYLE\5.4.28.3179\QYDOWNLOADPROXY.DLL

What is QYCLIENT.EXE?


QYCLIENT.EXE is reported and classified as malicious program (malware).
QYCLIENT.EXE actively resists detection and employs a number of techniques to ensure that you cannot remove QYCLIENT.EXE from infected computers.


How QYCLIENT.EXE got on your computer?


Phishing is the most common way for malware to infect computers.
It could be a fake email message that appears to be originated from Microsoft Customer Service, eBay, PayPal, Amazon, or even your bank or insurance company.
Fake emails that appear to come from the police, the FBI and other government entities were also reported.

QYCLIENT.EXE could also infect your computer by exploiting a security vulnerability of your Web browser or one of its plugins.
If this is the case, QYCLIENT.EXE would be injected into a Web page, and could get to your PC when you visited a malicious or hacked Web site.

QYCLIENT.EXE can be distributed with legitimate software that is repackaged by the scammers.
It could be downloaded from warez Web sites or download archives.

How do you know you have QYCLIENT.EXE on my computer?


QYCLIENT.EXE works in background. It does not appear as a window, does not have a shortcut.
QYCLIENT.EXE hides its existence from your eyes.

How to remove QYCLIENT.EXE?


It may not be easy!
Be careful!
Make a full backup of your PC before starting.

Remove QYCLIENT.EXE now!

Dmitry Sokolov:

I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.

Since that time I work every day to fix the issues that antiviruses cannot.

If your antivirus have not helped you solve the problem, you should try UnHackMe.

We are a small company and you can ask me directly, if you have any questions.

Testimonials

You can read UnHackMe testimonials here.