Backdoor

Backdoor.Win32.Farfli.akda removal guide

Malware Removal

The Backdoor.Win32.Farfli.akda is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Farfli.akda virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary

How to determine Backdoor.Win32.Farfli.akda?


File Info:

name: B61F2F2A1958F9CE6C77.mlw
path: /opt/CAPEv2/storage/binaries/00bc5f649d7424872fe1deef8eddee8f85e9d42c4f4024f0e66f027101d132db
crc32: 39151E43
md5: b61f2f2a1958f9ce6c774061700aea92
sha1: 60f7ca51defc3adf2def49e28887752417c7a3f7
sha256: 00bc5f649d7424872fe1deef8eddee8f85e9d42c4f4024f0e66f027101d132db
sha512: f9a3c75011597949c6c890ec480f78e47faaa31cd63b925a421c28ef7f15d7ca7e034632781cc9d6ea71132c71835a128eb1beaf3152f67dc4cbd2fd9ef1a839
ssdeep: 3072:foUGzRVHgCcnV5j9j0lvil2NnGfNGHqRy1zkeS1FpTa3q5tJHMC:nGzRxSVtp0l6whGfsKR+zkBpTaa5tJH5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D7F3F1D7562E621AC8CE72355F30AAE4C4F87ED545D6EE18EB8015CBEA39780E580337
sha3_384: 4b211464dcbfd47e3ac085e7d6685483f01d1de366082489d94342f63ea12e2d89aa22fc92978ffd3f52a5acaf60b855
ep_bytes: 60be00804c008dbe0090f3ff5783cdff
timestamp: 2011-09-08 10:56:41

Version Info:

0: [No Data]

Backdoor.Win32.Farfli.akda also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.Gamania.32670
MicroWorld-eScanTrojan.GenericKD.34359813
FireEyeGeneric.mg.b61f2f2a1958f9ce
CAT-QuickHealBackdoor.FarfliRI.S18574655
ALYacTrojan.GenericKD.34359813
MalwarebytesMalware.AI.3974003332
VIPREBackdoor.Win32.Zegost.n (v)
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.a1958f
BitDefenderThetaGen:NN.ZexaF.34160.kmIfaOOMZvdb
VirITTrojan.Win32.Generic.ALX
CyrenW32/Zegost.Z.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Farfli.AKZ
TrendMicro-HouseCallTROJ_SPNR.14GU13
ClamAVWin.Trojan.Farfli-6784100-0
KasperskyBackdoor.Win32.Farfli.akda
BitDefenderTrojan.GenericKD.34359813
NANO-AntivirusTrojan.Win32.Gamania.rgyve
SUPERAntiSpywareTrojan.Agent/Gen-Farfli
AvastWin32:BackDoor-AAM [Trj]
TencentBackdoor.Win32.Gh0st.a
Ad-AwareTrojan.GenericKD.34359813
EmsisoftTrojan.GenericKD.34359813 (B)
ComodoTrojWare.Win32.Magania.~AAD@f80tc
BaiduWin32.Trojan.Farfli.z
ZillyaBackdoor.Agent.Win32.31111
TrendMicroTROJ_SPNR.14GU13
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosML/PE-A + Troj/Zegost-Q
IkarusBackdoor.Win32.Zegost
JiangminBackdoor.Farfli.dyv
eGambitUnsafe.AI_Score_99%
AviraBDS/Backdoor.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.A9A4
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotBackdoor.Win32.A.Agent.161280[UPX]
GDataWin32.Trojan.PSE.1TN56XU
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bjlog.R11765
Acronissuspicious
McAfeeGenericRXLS-XX!B61F2F2A1958
VBA32TrojanPSW.Gamania
CylanceUnsafe
APEXMalicious
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazoTru0cnFzQn+3KoO6QZeZ7)
YandexTrojan.Farfli!f9gHPEJRaZs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/BackDoor.AAM!tr
AVGWin32:BackDoor-AAM [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Win32.Farfli.akda?

Backdoor.Win32.Farfli.akda removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment