Backdoor

Backdoor:Win32/Farfli.GMC!MTB removal tips

Malware Removal

The Backdoor:Win32/Farfli.GMC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Farfli.GMC!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Farfli.GMC!MTB?


File Info:

name: 6A605372AC3503D26939.mlw
path: /opt/CAPEv2/storage/binaries/33f83ecee35a605f7cebc818b1f9349c3b0e58c27b3cdae03593caf3c92c374c
crc32: E4F5BF82
md5: 6a605372ac3503d269399261c45476cb
sha1: 08742b22a7cd8f1d038e97ae95a2d28d02c2e822
sha256: 33f83ecee35a605f7cebc818b1f9349c3b0e58c27b3cdae03593caf3c92c374c
sha512: 0d7d68c8da805ddb3c357b40dae1b506072059b79fcab6088097f7020d800a82a410ec0558b1ae0672750c1ce727c58a920d6b8a89b5e6ed3965099afa117efb
ssdeep: 49152:4kf7U5ErXsGKePWvhay0IPsyhxO/2b67dcF3dtaSCrL:j7ikcGJPW5tUaG7y3dYr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0E5F1749AA21053E8F787B4A7B8CB58FD361F224BF064C5C357BE813A7416298249FD
sha3_384: e0b578ff6cb3292871e4186e22c518e81c4d5840ced22492740b4b190d44cc39cfd0100175bc9c1e575a769d09a3199d
ep_bytes: 3bc0741ceb00db2ddc654f00ffffffff
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Backdoor:Win32/Farfli.GMC!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
SkyhighBehavesLike.Win32.Generic.vc
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004b94951 )
K7GWTrojan ( 004b94951 )
Cybereasonmalicious.2a7cd8
VirITBackdoor.Win32.Hupigon5.CELK
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VProtect.B suspicious
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Vprotect-9832456-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.DamagedFile.belkdi
AvastWin32:Evo-gen [Trj]
F-SecureHeuristic.HEUR/AGEN.1359431
DrWebTrojan.Packed.1936
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.6a605372ac3503d2
SophosMal/VProtPck-B
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1359431
Antiy-AVLTrojan[Packed]/Win32.CryptExe
Kingsoftmalware.kb.a.1000
XcitiumPacked.Win32.VProtect.A@4xq3f8
MicrosoftBackdoor:Win32/Farfli.GMC!MTB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.12RF067
GoogleDetected
VBA32TScope.Malware-Cryptor.SB
Cylanceunsafe
RisingTrojan.Generic@AI.97 (RDML:c8VY6ljr5YRBghS8HAdleQ)
IkarusPUA.VProtect
MaxSecureVirus.Patched.OF
BitDefenderThetaGen:NN.ZexaF.36792.7wW@ai1XX!mb
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Farfli.GMC!MTB?

Backdoor:Win32/Farfli.GMC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment