Backdoor

Backdoor.Win32.Farfli.bwde removal guide

Malware Removal

The Backdoor.Win32.Farfli.bwde is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Farfli.bwde virus can do?

  • Executable code extraction
  • At least one process apparently crashed during execution
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
users.qzone.qq.com
ocsp.dcocsp.cn

How to determine Backdoor.Win32.Farfli.bwde?


File Info:

crc32: B574C85E
md5: a47b3810a696ee60e4491b2b53527cd2
name: A47B3810A696EE60E4491B2B53527CD2.mlw
sha1: 75245e7826d19af33d4cb44e4890e9ab1628fb7c
sha256: b3d5b8a55307146b0489bb5a5f642bae9dae19481effa036f5399d44f54d95e6
sha512: a7a55c0027c57a9134c4e4858d36da037142b1d44de06d64431dd7438ffe1bf2d56a02a71bb4911ab67e0931541090810086e76bbb88a90ddfff24500f15c6f4
ssdeep: 24576:1MrAA4wXwkvpQ1LN7ZIb3o10IIsak4KuifuJHC:X2xQJFSbFIJKKu0uo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Farfli.bwde also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005239691 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader40.27806
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005239691 )
Cybereasonmalicious.826d19
CyrenW32/Trojan.YESP-4547
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.NoobyProtect.M suspicious
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Farfli.bwde
SophosMal/Gee-A
ComodoTrojWare.Win32.Amtar.KNB@4wlm66
BitDefenderThetaGen:NN.ZexaF.34790.@uW@a0BPA2n
TrendMicroTROJ_GEN.R005C0RG621
McAfee-GW-EditionBehavesLike.Win32.Polybot.fc
FireEyeGeneric.mg.a47b3810a696ee60
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraBDS/Backdoor.Gen
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftTrojan.Heur!.03014021
GDataWin32.Packed.NoobyProtect.B
AhnLab-V3Trojan/Win32.Generic.C4291321
Acronissuspicious
McAfeeGenericRXAA-FA!A47B3810A696
MalwarebytesMalware.AI.1871383295
TrendMicro-HouseCallTROJ_GEN.R005C0RG621
RisingTrojan.Generic@ML.98 (RDML:INPirVd7VcO9RvSzrIpmrA)
IkarusPUA.NoobyProtect
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Farfli
AVGWin32:Malware-gen
Qihoo-360HEUR/QVM18.1.7BE3.Malware.Gen

How to remove Backdoor.Win32.Farfli.bwde?

Backdoor.Win32.Farfli.bwde removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment