Solved! Use YIMEISHI.DLL (Backdoor Farfli) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

YIMEISHI.DLL – Backdoor Farfli removal

FileMD5Virus Alias
YIMEISHI.DLL 0049d67c1764086b8496848f0f821812 Backdoor Farfli
YIMEISHI.DLL 0049d67c1764086b8496848f0f821812 Trojan UnwantedProgram
YIMEISHI.DLL 0049d67c1764086b8496848f0f821812 Trojan Eldorado
YIMEISHI.DLL 0049d67c1764086b8496848f0f821812 Trojan MMM
YIMEISHI.DLL 0049d67c1764086b8496848f0f821812 Trojan Agent
YIMEISHI.DLL 0049d67c1764086b8496848f0f821812 Backdoor Zegost

YIMEISHI.DLL size: 136789 bytes
YIMEISHI.DLL hash: 0049D67C1764086B8496848F0F821812

Created files:

C:\Documents and Settings\Local User\yimeishi.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\360svc\Type: 10000000
HKLM\System\CurrentControlSet\Services\360svc\Start: 02000000
HKLM\System\CurrentControlSet\Services\360svc\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\360svc\DisplayName: Microsoft Device Manager
HKLM\System\CurrentControlSet\Services\360svc\ImagePath: %SystemRoot%\System32\svchost.exe -k netsvcs
HKLM\System\CurrentControlSet\Services\360svc\Description: ?????????????????????????????????
HKLM\System\CurrentControlSet\Services\360svc\InstallModule: 0C8FF759025572D5DA7BF6068ECCE64A.EXE
HKLM\System\CurrentControlSet\Services\360svc\SBIE_Win32ExitCode: 02000000
HKLM\System\CurrentControlSet\Services\360svc\Parameters\ServiceDll: 43003A005C0044006F00630075006D0065006E0074007300200061006E0064002000530065007400740069006E00670073005C004C006F00630061006C00200055007300650072005C00790069006D00650069007300680069002E0064006C006C000000

Detected by UnHackMe:

YIMEISHI.DLL
Default location: C:\DOCUMENTS AND SETTINGS\LOCAL USER\YIMEISHI.DLL

Dropper information:
MD5: 0c8ff759025572d5da7bf6068ecce64a
File size: 145602 bytes

Leave a Reply