Solved! Use 2013800.DLL (Backdoor Farfli) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

2013800.DLL – Backdoor Farfli removal

File MD5 Virus Alias
2013800.DLL 6ebd768a125d26d85027be876ec58c9c Backdoor Farfli
2013800.DLL 6ebd768a125d26d85027be876ec58c9c Trojan PcClient
2013800.DLL 6ebd768a125d26d85027be876ec58c9c Trojan Eldorado
2013800.DLL 6ebd768a125d26d85027be876ec58c9c Trojan Barys
2013800.DLL 6ebd768a125d26d85027be876ec58c9c Backdoor PcClien
2013800.DLL 6ebd768a125d26d85027be876ec58c9c Trojan Magania

2013800.DLL size: 103936 bytes
2013800.DLL hash: 6EBD768A125D26D85027BE876EC58C9C

Created files:

C:\2013800.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\Please Input Service Name\Type: 10010000
HKLM\System\CurrentControlSet\Services\Please Input Service Name\Start: 02000000
HKLM\System\CurrentControlSet\Services\Please Input Service Name\DisplayName: Please Input Service Display
HKLM\System\CurrentControlSet\Services\Please Input Service Name\ImagePath: %SystemRoot%\System32\svchost.exe -k imgsvc
HKLM\System\CurrentControlSet\Services\RemoteAccess\RouterManagers\Ip\DLLPath: 43003A005C0032003000310033003800300030002E0064006C006C000000

Detected by UnHackMe:

2013800.DLL
Default location: C:\2013800.DLL

Dropper information:
MD5: d68a4115143bbbd1d20b6bef3e21b3b7
File size: 137216 bytes

Leave a Reply