Backdoor

How to remove “Backdoor.Win32.Farfli.bwam”?

Malware Removal

The Backdoor.Win32.Farfli.bwam is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Farfli.bwam virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Farfli.bwam?


File Info:

crc32: 91502A77
md5: 1a25b1207773f3d2f7716b468180b3c5
name: 1A25B1207773F3D2F7716B468180B3C5.mlw
sha1: 2f42429ad9ac8f4a0a71efed0c7dd8eb4b98e955
sha256: c0d4ba74f0c71e3feaffe17cbe05eeea3cabb12dc7fcb09addaef10dfdfe1315
sha512: 87b374f9ff8ddf4162da5800ef75f4a2aafbd32a8da6eb343b9ce2285b31e2e638e67e828f26dd82a970d494e21177f61ec528824cf60ea4b7b2aadff33449b5
ssdeep: 24576:nVMQw4P1N0MmSv+udZWfhQwILsxN0RpLKkp7KWHoFN6WtljaEy9Tu:nmQxNtmxuqfm5MqplhHoFN6WtljaEy9a
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998
InternalName: MyPad
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: MyPad Application
ProductVersion: 1, 0, 0, 1
FileDescription: MyPad MFC Application
OriginalFilename: MyPad.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Farfli.bwam also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005239691 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 004b8a501 )
Cybereasonmalicious.ad9ac8
CyrenW32/Trojan.DZQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.NoobyProtect.M suspicious
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Farfli.bwam
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Amtar.KNB@4wlm66
F-SecureHeuristic.HEUR/AGEN.1113339
BitDefenderThetaGen:NN.ZexaF.34770.lv0@aqx!lwoi
McAfee-GW-EditionBehavesLike.Win32.Injector.tc
FireEyeGeneric.mg.1a25b1207773f3d2
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1113339
eGambitUnsafe.AI_Score_99%
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftTrojan.Heur!.030100A1
ZoneAlarmBackdoor.Win32.Farfli.bwam
GDataWin32.Packed.NoobyProtect.B
AhnLab-V3Suspicious/Win.Generic.C4535311
Acronissuspicious
McAfeeGenericRXAA-FA!1A25B1207773
MalwarebytesMalware.AI.2957937952
TrendMicro-HouseCallTROJ_GEN.R005H0CFR21
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazouoaoDS1VYFbvBfp/Mdu42)
IkarusPUA.NoobyProtect
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Farfli
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor.Win32.Farfli.bwam?

Backdoor.Win32.Farfli.bwam removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment