A reader of Technize asked me about how to remove flashy.exe virus. First of all let’s see what exactly is flashy.exe. It’s a type of backdoor trojan for Windows Platform that tries to take control of the infected system. It runs a telnet server on the infected computer. It also changes the administrator password to “hacked”.

When first run it copies itself to:

<Startup>systemID.pif
<System>Flashy.exe

The following registry entry is created to run Flashy.exe on startup:

HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun
Flashy Bot <System>Flashy.exe

It changes the following registry:

HKLMSYSTEMCurrentControlSetServicesSharedAccess
Start
4

It disables folder options, sets hidden files to true and hides the file extensions.

How To Remove It?

Just download the following flashy.exe remover and run it. It will get rid of the culprit. It is recommended that you run this tool in safe mode.

Flashy Remover (80.4 KiB, 11,782 hits)

Technical Names Given By Security Companies:-

BackDoor-DIY [McAfee] W32/Glupzy-B [Sophos] WORM_FLASHY.B [Trend Micro] Trojan.Win32.Disabler.i [Kaspersky Lab] Email-Worm.Win32.Brontok.N [Ikarus] Win32.Virut.Gen.5 [PC Tools] Backdoor:Win32/Glupzy.A [Microsoft] Trojan.Win32.Disabler.al [Kaspersky Lab] W32/Vetor-A [Sophos] W32/Virut.gen [McAfee] Trojan.Disabler.E [PC Tools] Virus.Win32.Virut.n [Kaspersky Lab] Virus:Win32/Virut.AE [Microsoft] Win32.Dzan.A [PC Tools] Mal/HckPk-C [Sophos] Mal/Packer [Sophos] PE_VIRUT.XL [Trend Micro] PE_VIRUT.XP [Trend Micro] PE_VIRUT.XS [Trend Micro] TROJ_DISABLER.AD [Trend Micro] Trojan.Disabler!sd5 [PC Tools] Trojan.Disabler.O [PC Tools] Trojan.Disabler.T [PC Tools] Trojan.Win32.Agent.kkh [Kaspersky Lab] Trojan.Win32.Disabler.i [Ikarus] Trojan.Win32.Disabler.x [Kaspersky Lab] Trojan:Win32/Patched.AF [Microsoft] Virus.Win32.Virut.q [Kaspersky Lab] Virus:Win32/Virut.AF [Microsoft] Virus:Win32/Virut.K [Microsoft] W32/Glupzy-C [Sophos] [Reference]