Backdoor

Backdoor:Win32/Farfli.BZ removal tips

Malware Removal

The Backdoor:Win32/Farfli.BZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Farfli.BZ virus can do?

  • Executable code extraction
  • Drops a binary and executes it
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Backdoor:Win32/Farfli.BZ?


File Info:

crc32: C28A3EA4
md5: 0b5665cfe8d7df1b6df6b14cb54276b1
name: svchost.exe
sha1: 3ce225de0063f178e2ba1926616d93812426dead
sha256: 629e1232870afdc931758b23b4bdaa4ddd817b7833677513d1eb27f376dcc1ff
sha512: 11637494bb0bb2d0241c3333d0de6c15ed26afceea51e498e79d4fadc715c5b1d98e578033c92e7809084186e419e58a05b6d1f7b8bae8c03e6d06040cef2627
ssdeep: 1536:uc0yPmiHjdbxv7fjTHMB5RJGNoQ0u0M+xY7H56uDd4by+ik5S4BRChQM:ut4h3EpCH0u0MDN9xcQuRChQM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Farfli.BZ also known as:

MicroWorld-eScanGen:Variant.Graftor.721922
FireEyeGeneric.mg.0b5665cfe8d7df1b
McAfeeArtemis!0B5665CFE8D7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00521b151 )
BitDefenderGen:Variant.Graftor.721922
K7GWTrojan ( 00521b151 )
Cybereasonmalicious.e0063f
BitDefenderThetaGen:NN.ZexaF.34104.juX@aed4OSe
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EGZV
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Graftor.721922
KasperskyBackdoor.Win32.Lotok.bas
AlibabaTrojan:Win32/Injector.89ee13e1
ViRobotTrojan.Win32.Z.Lotok.155802
AegisLabTrojan.Win32.Lotok.m!c
RisingBackdoor.Farfli!8.B4 (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Graftor.721922 (B)
ComodoMalware@#2nsegkk9ngok5
F-SecureTrojan.TR/Injector.oksqf
DrWebTrojan.DownLoader33.21549
ZillyaTrojan.Injector.Win32.695167
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
CyrenW32/Trojan.SMAB-9045
JiangminBackdoor.Lotok.fl
AviraTR/Injector.oksqf
Antiy-AVLTrojan[Backdoor]/Win32.Lotok
MicrosoftBackdoor:Win32/Farfli.BZ
ArcabitTrojan.Graftor.DB0402
AhnLab-V3Trojan/Win32.Injector.R330706
ZoneAlarmBackdoor.Win32.Lotok.bas
Acronissuspicious
VBA32Backdoor.Lotok
ALYacGen:Variant.Graftor.721922
MAXmalware (ai score=87)
Ad-AwareGen:Variant.Graftor.721922
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R015H0CCV20
TencentMalware.Win32.Gencirc.10b90b37
YandexTrojan.Injector!slVUdWp4Ji8
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Lotok.BAS!tr.bdr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.683

How to remove Backdoor:Win32/Farfli.BZ?

Backdoor:Win32/Farfli.BZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment