Backdoor

Backdoor:Win32/Farfli.GMC!MTB information

Malware Removal

The Backdoor:Win32/Farfli.GMC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Farfli.GMC!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Farfli.GMC!MTB?


File Info:

name: 8D10AEAE0F5424063EAD.mlw
path: /opt/CAPEv2/storage/binaries/2c29e9fb5bb18800ae118c7de47b8a45f7426099cf4f66f000d1637619dba9e5
crc32: 55EFB2AA
md5: 8d10aeae0f5424063ead27ffcd25517c
sha1: 6478ec878d9768a3baaf8995c1039d3461a2953c
sha256: 2c29e9fb5bb18800ae118c7de47b8a45f7426099cf4f66f000d1637619dba9e5
sha512: 4978d0fe73b2809ba0fea05c2efd8b874b97deff3bc63bf4a4f002325e9caba54705f6798ecf4a421483ebee6b85ad48412415448e45a46d7f8a7b993e767ffa
ssdeep: 196608:5aEbM3zOrVgfAALu4aVpW+++Bd7oHWDDq:s/3aYcjOT0WWfq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1336612B4AA514416C4F10BB093B6CB68FD356F3247F059CAD3A37E8A3A7426399254FC
sha3_384: 6541bb3050333fa205d215431ca068d9a29de31cf7a5e059136bc57c85847a0973d224a020b4cf7e134d8de2a2c8bdd9
ep_bytes: 3bc0741ceb00db2ddc05b700ffffffff
timestamp: 1970-01-01 00:00:00

Version Info:

Comments: 通达信
CompanyName: (通达信)深圳市财富趋势科技股份有限公司
FileDescription: TDX 应用程序
FileVersion: 1, 0, 0, 1
InternalName: TDX
LegalCopyright:
LegalTrademarks: 通达信
OriginalFilename: tdxw.exe
PrivateBuild:
ProductName: TDX 应用程序
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Backdoor:Win32/Farfli.GMC!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lnLK
DrWebTrojan.Packed.1936
MicroWorld-eScanTrojan.GenericKD.69715180
FireEyeGeneric.mg.8d10aeae0f542406
SkyhighBehavesLike.Win32.Pate.vc
ALYacTrojan.GenericKD.69715180
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.69715180
SangforBackdoor.Win32.Farfli.Vppr
K7AntiVirusTrojan ( 004b94951 )
BitDefenderTrojan.GenericKD.69715180
K7GWTrojan ( 004b94951 )
Cybereasonmalicious.78d976
BitDefenderThetaGen:NN.ZexaF.36792.@x0@a045Scnb
VirITBackdoor.Win32.Hupigon5.CELK
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VProtect.B suspicious
APEXMalicious
ClamAVWin.Packed.Vprotect-9832456-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaBackdoor:Win32/Farfli.2f972e5d
NANO-AntivirusTrojan.Win32.DamagedFile.belkdi
RisingTrojan.Generic@AI.100 (RDML:bO2ilISGUCQLEhFP4mmbSg)
SophosMal/VProtPck-B
F-SecureBackdoor.BDS/Farfli.yyeng
ZillyaTrojan.VProtect.Win32.682
TrendMicroTROJ_GEN.R002C0DJ723
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.69715180 (B)
IkarusPUA.VProtect
GoogleDetected
AviraBDS/Farfli.yyeng
VaristW32/ABRisk.NFUY-4713
Antiy-AVLTrojan[Backdoor]/Win32.Farfli
MicrosoftBackdoor:Win32/Farfli.GMC!MTB
XcitiumPacked.Win32.VProtect.A@4xq3f8
ArcabitTrojan.Generic.D427C4EC
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.12RF067
CynetMalicious (score: 100)
McAfeeArtemis!8D10AEAE0F54
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
VBA32TScope.Malware-Cryptor.SB
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DJ723
TencentMalware.Win32.Gencirc.13f1afab
YandexTrojan.GenAsa!YDUAdxujHWw
SentinelOneStatic AI – Suspicious PE
MaxSecureVirus.Patched.OF
FortinetRiskware/Application
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Farfli.GMC!MTB?

Backdoor:Win32/Farfli.GMC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment