Backdoor

Should I remove “Backdoor.Win32.Farfli.ajly”?

Malware Removal

The Backdoor.Win32.Farfli.ajly is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Farfli.ajly virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Checks the system manufacturer, likely for anti-virtualization
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

39m0428g57.zicp.vip

How to determine Backdoor.Win32.Farfli.ajly?


File Info:

crc32: CA237732
md5: b48cc377d44062ef3d72bc849cf432d6
name: B48CC377D44062EF3D72BC849CF432D6.mlw
sha1: 6e1a6e9140a81b0fe104564fbbdc841efa932241
sha256: 1efcd78cd154b6277b8ccfe8a35614ab71c79023af879fa05d4d5fc3d663c124
sha512: 438314733bde1bcddea4a973a06a3225a061ef1ac844c9678d1757453327c4ab65657f5e73b135e3c48a8fd7c0327ca8a246c4fdc7c3ecc19a2ec1f3f4d82011
ssdeep: 192:4gHjClfSWngwc5YAfjy6HY41edKz7JJicZqohL5FX6:4QGtSZ5YAfZHxkdOmcRjX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Farfli.ajly also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader21.53580
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Agent.Win32.683982
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan-Downloader ( 0055e3da1 )
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
CyrenW32/Agent.ALL.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.CQX
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-6443182-0
KasperskyBackdoor.Win32.Farfli.ajly
BitDefenderTrojan.Cud.Gen.1
NANO-AntivirusTrojan.Win32.Farfli.elvztf
MicroWorld-eScanTrojan.Cud.Gen.1
TencentMalware.Win32.Gencirc.10b3cd79
Ad-AwareTrojan.Cud.Gen.1
ComodoTrojWare.Win32.Farfli.CQ@7y93vk
BitDefenderThetaGen:NN.ZexaF.34684.auW@aiwEl1ni
TrendMicroBKDR_ZEGOST.SM32
McAfee-GW-EditionTrojan-FJYJ!B48CC377D440
FireEyeGeneric.mg.b48cc377d44062ef
EmsisoftTrojan.Cud.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Generic.afkf
WebrootW32.Trojan.Gen
AviraTR/Downloader.Gen4
eGambitUnsafe.AI_Score_99%
MicrosoftTrojanDownloader:Win32/Nystprac.A
ArcabitTrojan.Cud.Gen.1
GDataTrojan.Cud.Gen.1
TACHYONBackdoor/W32.Farfli.13824
AhnLab-V3Trojan/Win32.Farfli.R182355
McAfeeTrojan-FJYJ!B48CC377D440
MAXmalware (ai score=84)
VBA32Backdoor.Farfli
MalwarebytesMalware.AI.521088740
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_ZEGOST.SM32
RisingBackdoor.Farfli!8.B4 (RDMK:cmRtazq7nXwjkqUn/sb7ZXdqO+r5)
YandexTrojan.GenAsa!jyx+fvnRphc
IkarusTrojan-Downloader.Win32.Agent
FortinetW32/GenKryptik.AGWJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor.Win32.Farfli.ajly?

Backdoor.Win32.Farfli.ajly removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment