Backdoor

Backdoor:Win32/Farfli.AX removal

Malware Removal

The Backdoor:Win32/Farfli.AX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Farfli.AX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Farfli.AX?


File Info:

crc32: C876B7A3
md5: a2c39eafd7f99e40605d8020ba9f7b7e
name: A2C39EAFD7F99E40605D8020BA9F7B7E.mlw
sha1: 082875a55b258c26a9be1a38a58b95390c188b6f
sha256: 870bd52f6aeeba784395b89758dfd4efaf718df37760098c7abd1a453e0b33ce
sha512: e6ffa343f7dbfd0b758f87cf94f3600601b4a1bb253b7614e7a84fa6b570fbb8c2bb63ad006026a14bcff4a3d8170573419630830e7f06be823fc87f99f0748a
ssdeep: 24576:EwdyXPJqp1yZS/Bze9sVqztbYzueh+4XXRsmGfaDAJ1F+eiPdEmw38K:EwdwPJAsZSw9AXbR1GfqRlEmwMK
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2005
InternalName: MVCSphere
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: MVCSphere x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: MVCSphere Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: MVCSphere.EXE
Translation: 0x0804 0x04b0

Backdoor:Win32/Farfli.AX also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 90)
ALYacDeepScan:Generic.Keylogger.2.D246211D
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (W)
Cybereasonmalicious.fd7f99
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HDPV
APEXMalicious
AvastWin32:Trojan-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderDeepScan:Generic.Keylogger.2.D246211D
MicroWorld-eScanDeepScan:Generic.Keylogger.2.D246211D
Ad-AwareDeepScan:Generic.Keylogger.2.D246211D
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34608.gDNaaq@ukLib
McAfee-GW-EditionBehavesLike.Win32.Injector.tc
FireEyeGeneric.mg.a2c39eafd7f99e40
EmsisoftDeepScan:Generic.Keylogger.2.D246211D (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1134990
eGambitUnsafe.AI_Score_97%
MicrosoftBackdoor:Win32/Farfli.AX
GridinsoftPack.Win32.Gen.bot!ep-45894
ArcabitDeepScan:Generic.Keylogger.2.D246211D
GDataWin32.Trojan-Spy.Keylogger.TH4XFB
McAfeeArtemis!A2C39EAFD7F9
MAXmalware (ai score=83)
VBA32BScope.Backdoor.Farfli
MalwarebytesMalware.Heuristic.1003
RisingTrojan.Kryptik!1.C71D (CLASSIC)
IkarusTrojan-PWS.Win32.Executant.d
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HDPV!tr
AVGWin32:Trojan-gen
Qihoo-360Win32/Backdoor.Farfli.HxIB1j8A

How to remove Backdoor:Win32/Farfli.AX?

Backdoor:Win32/Farfli.AX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment