Backdoor

Backdoor:Win32/Farfli.BW!MTB information

Malware Removal

The Backdoor:Win32/Farfli.BW!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Farfli.BW!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Farfli.BW!MTB?


File Info:

name: 8B55F6F3D1E0A3FFA56A.mlw
path: /opt/CAPEv2/storage/binaries/1fad15074bc9ac411aabee229abb25341a2964e67e8ad86c0ccd7d2a9ac624a4
crc32: C0F30505
md5: 8b55f6f3d1e0a3ffa56a661a0356aa6f
sha1: 91b8e6bc331a6420b2647a300653b728e3f52d58
sha256: 1fad15074bc9ac411aabee229abb25341a2964e67e8ad86c0ccd7d2a9ac624a4
sha512: 3ae8ddd0f8730335a7e09b027568c150778b2ed4a4d7546b5383eede9b077cc484c0522fd3db124e0de75a9671c3fdd995b81b11b3d1fcecb7db20cc3a140bce
ssdeep: 24576:/SCNRNGR1Yk80WX9ihBjR5vF8YDBZcpopTl4qnhIe/cMETAmN6rS:zDWYk87ojPuABJhnGGcVTbNeS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12E859D12B7D1807EC1A34331DD58B7A466FEFE324930835BA7983B1C1E71AC2AE15766
sha3_384: 7a402d55ab0148b114b656489e16d0624a0048801334b522d193bb77cc9530ceefb8372d7631e444c9b0ea416b3f0cdd
ep_bytes: 558bec6aff68080e4100687ce0400064
timestamp: 2019-03-01 11:40:13

Version Info:

Comments:
CompanyName: Windows 用户
FileDescription: MFCTEST
FileVersion: 5, 0, 0, 1
InternalName: MFCTEST
LegalCopyright: 版权所有(C) 2019
LegalTrademarks:
OriginalFilename: Install.dat
PrivateBuild:
ProductName: Windows 用户 MFCTEST
ProductVersion: 5, 0, 0, 1
SpecialBuild:
Translation: 0x0405 0x04b0

Backdoor:Win32/Farfli.BW!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Lotok.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68384968
FireEyeGeneric.mg.8b55f6f3d1e0a3ff
CAT-QuickHealBackdoor.Farfli
ALYacTrojan.GenericKD.68384968
Cylanceunsafe
ZillyaBackdoor.Farfli.Win32.8502
SangforBackdoor.Win32.Farfli.Va31
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Zegost.60471228
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderThetaGen:NN.ZexaF.36318.Qr0@aqaLZipb
CyrenW32/ABRisk.KLXF-5388
ESET-NOD32a variant of Win32/Farfli.CML
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Backdoor.Win32.Lotok.gen
BitDefenderTrojan.GenericKD.68384968
NANO-AntivirusTrojan.Win32.Staser.fnuroh
AvastWin32:MalwareX-gen [Trj]
TencentMalware.Win32.Gencirc.10baabab
EmsisoftTrojan.GenericKD.68384968 (B)
F-SecureTrojan.TR/Farfli.arvsv
DrWebTrojan.Damaged.1
VIPRETrojan.GenericKD.68384968
TrendMicroTROJ_GEN.R002C0DGP23
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.Win32.Farfli
GDataTrojan.GenericKD.68384968
JiangminBackdoor.Generic.auhq
WebrootW32.Malware.Gen
AviraTR/Farfli.arvsv
MAXmalware (ai score=86)
Antiy-AVLTrojan[Backdoor]/Win32.Farfli
ArcabitTrojan.Generic.D41378C8
ViRobotTrojan.Win.Z.Farfli.1748992
ZoneAlarmHEUR:Backdoor.Win32.Generic
MicrosoftBackdoor:Win32/Farfli.BW!MTB
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C3055809
McAfeeArtemis!8B55F6F3D1E0
VBA32BScope.Trojan.MulDrop
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DGP23
RisingBackdoor.Zegost!8.177 (TFE:5:EzLlmDqgHfB)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.7175197.susgen
FortinetW32/Farfli.BSIK!tr
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Farfli.BW!MTB?

Backdoor:Win32/Farfli.BW!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment