Backdoor

What is “Backdoor.Win32.Farfli.brjz”?

Malware Removal

The Backdoor.Win32.Farfli.brjz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Farfli.brjz virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Farfli.brjz?


File Info:

crc32: 9D59B2DA
md5: fcef63f2e78e5b1d5cbb9d585906e8be
name: FCEF63F2E78E5B1D5CBB9D585906E8BE.mlw
sha1: f9372bc5e1c38ffd0f85b82a78801f3c994f04b3
sha256: 61512d5358d147b075736e01bf9708bc0029ea6360c69f7af09a920b11087efb
sha512: 9bd2bb903a57d131a24374300898f586eb81ae24f17d2eba1a5be4858a12b5ffbf065b9377dfe57de6842e2ff349296a500c8209b5207f9911d7c42765ce1808
ssdeep: 6144:lBABAdbouCA9dctS6HrFGDrbyyu6vzTr5dNKTToAH6s:lmB0OCW1gDpu6nrcVas
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Wextract
FileVersion: 6.00.3790.0 (srv03_rtm.030324-2048)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.00.3790.0
FileDescription: Win32 Cabinet Self-Extractor
OriginalFilename: WEXTRACT.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Farfli.brjz also known as:

MicroWorld-eScanGen:Variant.Graftor.494720
FireEyeGen:Variant.Graftor.494720
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXAA-AA!FCEF63F2E78E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Farfli.m!c
SangforMalware
K7AntiVirusTrojan ( 005376ae1 )
BitDefenderGen:Variant.Graftor.494720
K7GWTrojan ( 005376ae1 )
CrowdStrikewin/malicious_confidence_70% (W)
Invinceaheuristic
F-ProtW32/Agent.BTG.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Graftor.494720
KasperskyBackdoor.Win32.Farfli.brjz
AlibabaBackdoor:Win32/Farfli.714bbf86
NANO-AntivirusTrojan.Win32.BlackMoon.flthzb
TencentMalware.Win32.Gencirc.10b9c3cb
Endgamemalicious (moderate confidence)
SophosTroj/Agent-BEJP
ComodoBackdoor.Win32.Zegost.XP@7o7w19
F-SecureHeuristic.HEUR/AGEN.1115359
DrWebBackDoor.BlackMoon.15
ZillyaWorm.Palevo.Win32.124018
TrendMicroTROJ_GEN.R002C0DE120
McAfee-GW-EditionBehavesLike.Win32.Fake.dc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.494720 (B)
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.WDZH-7669
JiangminBackdoor.Androm.algc
MaxSecureTrojan.Malware.7177504.susgen
AviraHEUR/AGEN.1115359
WebrootW32.Malware.gen
Antiy-AVLTrojan/Win32.APosT
ArcabitTrojan.Graftor.D78C80
ZoneAlarmBackdoor.Win32.Farfli.brjz
MicrosoftTrojan:Win32/Farfli.RSK!MTB
AhnLab-V3Backdoor/Win32.RL_Farfli.R333331
Acronissuspicious
VBA32Trojan.APosT
ALYacGen:Variant.Graftor.494720
Ad-AwareGen:Variant.Graftor.494720
MalwarebytesBackdoor.Farfli
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GGXP
TrendMicro-HouseCallTROJ_GEN.R002C0DE120
RisingBackdoor.Farfli!8.B4 (CLOUD)
YandexTrojan.Kryptik!h9wctYwL3eU
MAXmalware (ai score=87)
eGambitUnsafe.AI_Score_55%
FortinetW32/Kryptik.GGXP!tr
AVGWin32:Malware-gen
Cybereasonmalicious.2e78e5
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.600

How to remove Backdoor.Win32.Farfli.brjz?

Backdoor.Win32.Farfli.brjz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment