Available for Windows and Mac OS X users

Oct 8, 2015 07:04 GMT  ·  By

If you suspect you've been affected by the YiSpecter iOS malware, then besides being a careless iPhone owner, you now have a free tool at your disposal for removing this nasty infection.

The tool is named zYiRemoval and was created by Zimperium, the same company that's well known in the Android world for discovering the Stagefright (version 1 and 2.0) vulnerabilities.

The way the tool works is quite simple and relies on users downloading a ZIP archive, decompressing it, and running the tool in the OS' command-line. Your infected iOS device needs to be connected to the computer on which you run this tool.

The tool performs a series of operations, which users can also perform manually.

Uninstall any of these profiles (if present on your device):

  • Changzhou Wangyi Information Technology Co., Ltd.
  • Baiwochuangxiang Technology Co., Ltd.
  • Beijing Yingmob Interaction Technology Co.,  ltd.

Uninstall any of these apps (if present on your device):

  • 情涩播放器
  • 快播私密版
  • 快播0
  • HYQvod (bundle id: weiying.Wvod)
  • DaPian (bundle id: weiying.DaPian)
  • NoIcon (bundle id: com.weiying.hiddenIconLaunch)
If you found NoIcon installed, then you need to uninstall these two apps as well, which were silently installed on your device:  
  • ADPage (bundle id:  com.weiying.ad)
  • NoIconUpdate (bundle id: com.weiying.noiconupdate)
Two versions of zYiRemoval are provided, one for running on Windows PCs, and one for Macs.

Because the download links contain version numbers, we won't provide the download links here. zYiRemoval can be downloaded on Zimperium's blog, where the links will be updated by the company's security researchers when new versions of the tool come out.

Don't forget to update your device to iOS 9.0.2.

zYiRemoval in action
zYiRemoval in action

Photo Gallery (2 Images)

Remove YiSpecter from your device with Zimperium's zYiRemoval
zYiRemoval in action
Open gallery