Backdoor

What is “Backdoor:Win32/Farfli.AAB!MTB”?

Malware Removal

The Backdoor:Win32/Farfli.AAB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Farfli.AAB!MTB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor:Win32/Farfli.AAB!MTB?


File Info:

name: E03F4AB3FB52BD587CF7.mlw
path: /opt/CAPEv2/storage/binaries/3777db626858828af1d9b7bd7f95decc2a67c7f74465704e071992c759bc0399
crc32: 6FF5F550
md5: e03f4ab3fb52bd587cf72ae9fa4162bf
sha1: 9abdb1688f03731d3bf9826bb224ae057a63cae7
sha256: 3777db626858828af1d9b7bd7f95decc2a67c7f74465704e071992c759bc0399
sha512: 2fff29f3f54fd1161d5fb0a0ffc141a3c5a2810bb411691622aaed0bbeec605d9e6e7c91459992b826ccbc4bb3513c3198cf5e2fbf9cb66adb625815781a811b
ssdeep: 3072:9fLbI2j+jKP1RestXdfTDqYQ+kfCwxPiD1LrXAJ2I0:9TU2j+jKtxHqVbCwxPiZnAs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6D38D1EBA8080BBE0E5153CA8973B3ED77BA9F05969CD43FB24478D1AB4549DA30707
sha3_384: 481376966c77058f482cbc49feb8732960f5e3bb07adfc1300614a186157ed812a609fd7e54ed7e51aa96a4f426051be
ep_bytes: 558bec6aff682818400068d039400064
timestamp: 2010-12-13 00:42:54

Version Info:

CompanyName: tzuk
FileDescription: Sandboxie Installer
FileVersion: 3.28.04
LegalCopyright: Copyright © Ronen Tzur
ProductName: Sandboxie
Translation: 0x0409 0x04e4

Backdoor:Win32/Farfli.AAB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lLJx
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.103806
FireEyeGeneric.mg.e03f4ab3fb52bd58
CAT-QuickHealTrojan.Aksula.A
SkyhighBehavesLike.Win32.Ipamor.ch
McAfeeGenericRXCK-CI!E03F4AB3FB52
MalwarebytesMalware.AI.907222389
ZillyaTrojan.MaganiaGen.Win32.1
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0055e3e41 )
BitDefenderTrojan.GenericKDZ.103806
K7GWTrojan ( 0055e3e41 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Backdoor.Agent.a
VirITBackdoor.Win32.Generic13.XEJ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDropper.Agent.PFE
APEXMalicious
ClamAVWin.Dropper.Gh0stRAT-6992317-0
KasperskyTrojan-Spy.Win32.KeyLogger.avyo
AlibabaTrojanSpy:Win32/Farfli.2090527e
NANO-AntivirusTrojan.Win32.Magania.hbcng
ViRobotTrojan.Win32.A.PSW-Magania.139465
AvastWin32:RATX-gen [Trj]
RisingBackdoor.Agent!1.65E6 (CLASSIC)
EmsisoftTrojan.GenericKDZ.103806 (B)
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.DownLoader1.48711
VIPRETrojan.GenericKDZ.103806
TrendMicroTROJ_GEN.R002C0DKA23
Trapminemalicious.high.ml.score
SophosMal/Redos-H
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
JiangminBackdoor/PcClient.afai
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Spy.Gen
VaristW32/OnlineGames.HL.gen!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.Inject
KingsoftWin32.Troj.Undef.a
MicrosoftBackdoor:Win32/Farfli.AAB!MTB
XcitiumTrojWare.Win32.Farfli.AEV@57ttfi
ArcabitTrojan.Generic.D1957E
ZoneAlarmTrojan-Spy.Win32.KeyLogger.avyo
GDataTrojan.GenericKDZ.103806
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Inject.R18004
VBA32BScope.Trojan.DDoS.Nitol
ALYacTrojan.GenericKDZ.103806
TACHYONTrojan-PWS/W32.WebGame.139481
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DKA23
TencentMalware.Win32.Gencirc.115e74f9
YandexTrojan.GenAsa!EasUmD+RpuM
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Redosdru.BED!tr
BitDefenderThetaAI:Packer.D2A9E4641F
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.88f037
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Farfli.AAB!MTB?

Backdoor:Win32/Farfli.AAB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment