Backdoor

Backdoor:Win32/Farfli.BX removal instruction

Malware Removal

The Backdoor:Win32/Farfli.BX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Farfli.BX virus can do?

  • At least one process apparently crashed during execution
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
client.yaap.co.uk

How to determine Backdoor:Win32/Farfli.BX?


File Info:

crc32: 17215A33
md5: 1af738d859d707269009a64b8966f2b2
name: luc.exe
sha1: 4d4ad6452e18dcb1625636f314e2e742a3756eb3
sha256: 35536be672a1450591fea9236c5571cb3c3f0757efd78a1a9ade570d8d018c46
sha512: 899b3e4d389070f27e92f5dff016805c90c5804dd7d85437efd64d1dd7bda59e8f9a6fe0a52d972d65e50c24d71723dd263a109eb03e688d71e472446a9b2d9d
ssdeep: 3072:q9XtCU9lyCghf02PUINVUP5GbST5pQDhjsAifmGb+eC2GGGGGGGGGeOA:q9X8U7yCebrNVUP005whI9fmGb+12GGR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2010
InternalName: XLBugReport
FileVersion: 2, 2, 0, 10
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: x8fc5x96f7x9519x8befx62a5x544a
SpecialBuild:
ProductVersion: 2, 2, 0, 10
FileDescription: x8fc5x96f7x9519x8befx62a5x544a
OriginalFilename: XLBugReport.exe
Translation: 0x0804 0x04b0

Backdoor:Win32/Farfli.BX also known as:

DrWebTrojan.DownLoader33.6854
MicroWorld-eScanGen:Variant.Strictor.33992
FireEyeGeneric.mg.1af738d859d70726
CAT-QuickHealBackdoor.Farfli.O
Qihoo-360Win32/Backdoor.d55
ALYacGen:Variant.Strictor.33992
MalwarebytesBackdoor.Farfli
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.m!c
SangforMalware
K7AntiVirusTrojan ( 00453f9b1 )
BitDefenderGen:Variant.Strictor.33992
K7GWTrojan ( 00453f9b1 )
Cybereasonmalicious.859d70
TrendMicroBKDR_ZEGOST.SM26
BitDefenderThetaGen:NN.ZexaF.34090.lq1@aahVjGbb
CyrenW32/Trojan.LYFD-6769
APEXMalicious
AvastWin32:Downloader-UAC [Trj]
GDataGen:Variant.Strictor.33992
KasperskyTrojan.Win32.Agentb.jwpy
AlibabaBackdoor:Win32/Farfli.266d6a22
NANO-AntivirusTrojan.Win32.Graftor.hcokar
ViRobotTrojan.Win32.Z.Farfli.184459
TencentWin32.Trojan.Agentb.Eclb
Ad-AwareGen:Variant.Strictor.33992
SophosMal/Generic-S
ComodoTrojWare.Win32.Zegost.WIX@522kpl
F-SecureTrojan.TR/Graftor.EB.40
BaiduWin32.Trojan.Farfli.t
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Strictor.33992 (B)
IkarusBackdoor.Win32.Inject
JiangminBackdoor.Generic.bbid
WebrootW32.Trojan.Gen
AviraTR/Graftor.EB.40
Antiy-AVLTrojan[Backdoor]/Win32.Farfli
Endgamemalicious (high confidence)
ArcabitTrojan.Strictor.D84C8
ZoneAlarmTrojan.Win32.Agentb.jwpy
MicrosoftBackdoor:Win32/Farfli.BX
AhnLab-V3Trojan/Win32.Zegost.R99356
Acronissuspicious
McAfeeFarfli.gen.a
MAXmalware (ai score=100)
VBA32BScope.TrojanDDoS.Macri
PandaTrj/GdSda.A
ESET-NOD32Win32/Farfli.AFC
TrendMicro-HouseCallBKDR_ZEGOST.SM26
RisingBackdoor.Farfli!1.64D7 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitTrojan.Generic
FortinetW32/Farfli.AJY!tr
AVGWin32:Downloader-UAC [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.75070196.susgen

How to remove Backdoor:Win32/Farfli.BX?

Backdoor:Win32/Farfli.BX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment