Backdoor

About “Backdoor.Win32.Farfli.ceig” infection

Malware Removal

The Backdoor.Win32.Farfli.ceig is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Farfli.ceig virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • CAPE detected the VMProtectStub malware family

How to determine Backdoor.Win32.Farfli.ceig?


File Info:

name: 7294E19B032BF59352B1.mlw
path: /opt/CAPEv2/storage/binaries/4117f3576926d28d5592d49c49d376781ea6dfddadb9d58278bee834dce399eb
crc32: 6BF79BF4
md5: 7294e19b032bf59352b1c7b722e9f29e
sha1: 5e892e9e775ec7219f27f4007dc8d8021cf22d41
sha256: 4117f3576926d28d5592d49c49d376781ea6dfddadb9d58278bee834dce399eb
sha512: c3b40d04744f546e611637fd8d02f527a1e7db2345163e3b080a552b45bbeac369563570534a41f26652000ba9c3478ea6e6a7b181aeb774a490bc8f69a015ee
ssdeep: 393216:h9Da8xPdaEiPzP+ToQHF8idgPzYbAGuemCv:d1aEiLGTXF8irAzS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180E633F6184AFD5FC1672A79CA249ACD4A1CF1427C5029237AD60F0CB6D4D2EC8F5E82
sha3_384: 5aea9095514108d60677aa193f6501a3fc7638c39b9eb92b9ee0a210a4f752c81cdd4de431bd791a30421777d7f746f2
ep_bytes: e9541ce000609c9ce829440000e92fbf
timestamp: 2022-10-02 11:53:51

Version Info:

0: [No Data]

Backdoor.Win32.Farfli.ceig also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen18.54324
FireEyeGeneric.mg.7294e19b032bf593
McAfeeArtemis!7294E19B032B
CylanceUnsafe
K7AntiVirusTrojan ( 7000001c1 )
AlibabaPacked:Win32/VMProtect.af026264
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.e775ec
BitDefenderThetaGen:NN.ZexaF.34698.@xW@aOZBqil
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.VMProtect.ABO
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Farfli.ceig
AvastFileRepMalware [Misc]
TencentWin32.Backdoor.Farfli.Vmhl
SophosMal/VMProtBad-A
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Spy.KrBanker.NPI4TP
GoogleDetected
AviraTR/Black.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.397A
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
MalwarebytesMalware.Heuristic.1003
ZonerProbably Heur.ExeHeaderL
RisingTrojan.Generic@AI.100 (RDML:v16hoWlzmC1nX+SyrpO1Ew)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGFileRepMalware [Misc]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Backdoor.Win32.Farfli.ceig?

Backdoor.Win32.Farfli.ceig removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment