Backdoor

Backdoor:Win32/Farfli.BI!MTB removal

Malware Removal

The Backdoor:Win32/Farfli.BI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Farfli.BI!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Backdoor:Win32/Farfli.BI!MTB?


File Info:

name: A503C99F3ACDF817676D.mlw
path: /opt/CAPEv2/storage/binaries/9606fb7343b1ea49eb7bcf61c85488eb2b42beb46c3460e13dd1bbbe425e08d5
crc32: 5B8C6650
md5: a503c99f3acdf817676dd8b1e958a534
sha1: c4377461ab69bbe605ef793485eb2264e7d8f369
sha256: 9606fb7343b1ea49eb7bcf61c85488eb2b42beb46c3460e13dd1bbbe425e08d5
sha512: 9de81eef0c69fad84010ac51498064308b0cb3d01bc94dfb88649157a775b474ae6ce8bd05247be26c108edf9efc09ccec1c4397e6bfe3d57ddf62665bf179c7
ssdeep: 24576:ugKAwvCXbZpIN/tSmnPaj2EKxSRes3spRK9zQHvWEjOERzOAQ8lzYG5Bpaiy4YPV:fKrCXEIjOeKoMHmqQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EAE51910B7009129D8BB21F94BAE726D610DE9D00744E1CB51C85AFEDFF9AF27D3918A
sha3_384: 885ac3b89a5674c178e841c3a683bac93b10fdcacbc8348d94de3e20babb3d6548ad20e23114e4ab0fb6a8e7a0fde688
ep_bytes: e944be1700e97f4a1300e9ba0c1200e9
timestamp: 2022-10-20 15:03:12

Version Info:

CompanyName:
FileDescription: sport Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: sport
LegalCopyright: 版权所有 (C) 2009
LegalTrademarks:
OriginalFilename: sport.EXE
ProductName: sport 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Backdoor:Win32/Farfli.BI!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tedy.181348
FireEyeGen:Variant.Tedy.181348
ALYacGen:Variant.Tedy.181348
SangforTrojan.Win32.Injector.BLQC
BitDefenderGen:Variant.Tedy.181348
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BLQC
APEXMalicious
KasperskyTrojan-Ransom.Win32.Blocker.yvrc
RisingTrojan.Generic@AI.86 (RDML:EHZ0sl9QtE8ROfufR7BxYA)
Ad-AwareGen:Variant.Tedy.181348
SophosMal/Generic-S
VIPREGen:Variant.Tedy.181348
TrendMicroRansom_Blocker.R011C0DJN22
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Tedy.181348 (B)
IkarusTrojan.Win32.Injector
JiangminHeur:Backdoor/Agent
AviraTR/AD.Farfli.ugkdx
MicrosoftBackdoor:Win32/Farfli.BI!MTB
ArcabitTrojan.Tedy.D2C464
GDataGen:Variant.Tedy.181348
GoogleDetected
McAfeeArtemis!A503C99F3ACD
MAXmalware (ai score=81)
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Blocker.R011C0DJN22
TencentWin32.Trojan.Blocker.Gkjl
FortinetW32/BLQC!tr
BitDefenderThetaGen:NN.ZexaF.34726.!E0@aCzbURpj
AVGWin32:RATX-gen [Trj]
AvastWin32:RATX-gen [Trj]

How to remove Backdoor:Win32/Farfli.BI!MTB?

Backdoor:Win32/Farfli.BI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment