Trojan

About “TrojanDropper:Win32/Farfli.E” infection

Malware Removal

The TrojanDropper:Win32/Farfli.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Farfli.E virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDropper:Win32/Farfli.E?


File Info:

name: BE92F12C27789FED1401.mlw
path: /opt/CAPEv2/storage/binaries/c211dfeace13a81673abb5a609de0fd94bb6a4a9a31f9db11687916f215a46b9
crc32: B42AC729
md5: be92f12c27789fed140195ef17803dbe
sha1: b6a28c1aef0e1ba6a95deb4625bf39d2c3ca02ec
sha256: c211dfeace13a81673abb5a609de0fd94bb6a4a9a31f9db11687916f215a46b9
sha512: 1227413e640158ee2c5174f53cb77c54e57092be7d08a4720b38602d8c93e96403925080b5f742c37b2d4b91652379bc95a51c53db99b9efd778d4145d95a356
ssdeep: 3072:tvUHexyY1t/Vvh8Q3aHS4ktdH5lfZbh0tt2/Y4xeIKhYOZLwAo6cCPeqov:dUSxrayjdZ1ZbWi/vxrK7ZLwtqeqo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD047E22FED040FAE595153C10A73B369A7FBD74CB496A43E764F95A0C32584BF22287
sha3_384: 9e1aaf3e9913ff434c97dc8087362a30f4a083bc9c4f5b91a63aaec803dc297f77cb6e934444d72aff4577b26b909b8a
ep_bytes: 558bec6aff6840714000686433400064
timestamp: 2011-07-27 15:54:31

Version Info:

Comments:
CompanyName: Sogou.com Inc.
FileDescription: 搜狗拼音输入法 设置程序
FileVersion: 5.0.0.3787
InternalName: SogouPY Config
LegalCopyright: ? 2010 Sogou.com Inc. All rights reserved.
LegalTrademarks:
OriginalFilename: Config.exe
PrivateBuild:
ProductName: 搜狗拼音输入法
ProductVersion: 5.0.0.3787
SpecialBuild:
Translation: 0x0804 0x04b0

TrojanDropper:Win32/Farfli.E also known as:

BkavW32.AIDetectMalware
CynetMalicious (score: 100)
FireEyeGeneric.mg.be92f12c27789fed
CAT-QuickHealBackdoor.Farfli.O
McAfeeGenericRXAA-AA!BE92F12C2778
Cylanceunsafe
VIPREDropped:Backdoor.Generic.693269
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004e44671 )
K7GWTrojan ( 004e44671 )
Cybereasonmalicious.aef0e1
BaiduWin32.Trojan.Farfli.ap
VirITBackdoor.Win32.Generic.ONR
CyrenW32/Trojan.UCLW-5861
SymantecBackdoor.Trojan
Elasticmalicious (high confidence)
ESET-NOD32Win32/Farfli.LK
APEXMalicious
ClamAVWin.Trojan.Farfli-9831751-0
KasperskyTrojan-GameThief.Win32.Magania.uasf
BitDefenderDropped:Backdoor.Generic.693269
NANO-AntivirusTrojan.Win32.Magania.cwujlt
MicroWorld-eScanDropped:Backdoor.Generic.693269
AvastWin32:Farfli-AX [Trj]
TencentTrojan.Win32.Magania.az
SophosML/PE-A
F-SecureBackdoor.BDS/Farfli.kj.2
DrWebTrojan.DownLoader5.58028
ZillyaTrojan.Magania.Win32.40601
TrendMicroBKDR_ZEGOST.SMT
McAfee-GW-EditionBackDoor-CKB.k
Trapminesuspicious.low.ml.score
EmsisoftDropped:Backdoor.Generic.693269 (B)
IkarusTrojan-Dropper.Agent
GDataDropped:Backdoor.Generic.693269
JiangminTrojan/PSW.Magania.aydk
WebrootTr/Pws.Magania.E
AviraBDS/Farfli.kj.2
Antiy-AVLTrojan[GameThief]/Win32.Magania
XcitiumTrojWare.Win32.Farfli.LK@4pmigc
ArcabitBackdoor.Generic.DA9415
ViRobotTrojan.Win32.A.PSW-Magania.59954
ZoneAlarmTrojan-GameThief.Win32.Magania.uasf
MicrosoftTrojanDropper:Win32/Farfli.E
GoogleDetected
AhnLab-V3Dropper/OnlineGameHack20.Gen
BitDefenderThetaGen:NN.ZedlaF.36722.gu8@a4T5YBbb
ALYacDropped:Backdoor.Generic.693269
MAXmalware (ai score=84)
VBA32BScope.Trojan.Downloader
MalwarebytesFarFli.Backdoor.Bot.DDS
PandaW32/P2PWorm.QD.worm
TrendMicro-HouseCallBKDR_ZEGOST.SMT
RisingBackdoor.Farfli!1.6531 (CLASSIC)
YandexTrojan.Farfli!q1J30Cw9fwc
MaxSecureTrojan.Malware.2599183.susgen
FortinetW32/Farfli.LK!tr
AVGWin32:Farfli-AX [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove TrojanDropper:Win32/Farfli.E?

TrojanDropper:Win32/Farfli.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment