Backdoor

Backdoor:WinNT/Farfli.B!sys (file analysis)

Malware Removal

The Backdoor:WinNT/Farfli.B!sys is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:WinNT/Farfli.B!sys virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Backdoor:WinNT/Farfli.B!sys?


File Info:

name: EAD884D6E2EE396FA9A2.mlw
path: /opt/CAPEv2/storage/binaries/0dbdb91d8b947fb95b62c4b1e15b74f0030aec1e47633fabd61862f7d788a697
crc32: DB5A88E9
md5: ead884d6e2ee396fa9a2a0fcce548f48
sha1: e9075b3bcb07f8098b9b24cbd9672eb7e8e983b4
sha256: 0dbdb91d8b947fb95b62c4b1e15b74f0030aec1e47633fabd61862f7d788a697
sha512: a6485e39a685f024b6f1a19484982d172b8f9da69bf53923a5afa423f53da938887b3e9826906d0de2ff9cf4009570ac8725941af0050da0271a90309cca07cb
ssdeep: 384:RnxX9/ZKQYnc3YUJtIFbGrbw7faM1wu0QuVNen0tWBoSuQjEQ5zq6SX/Xk0jogR5:Rt1mlGrG1w4nTpjHAHMDkyXdmzz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EBA20818EA0DBC95C4C7497E55B72C42F7F605FB076A43AB8F4A61253F78F10824B60A
sha3_384: 77fc55895adc728a70ddf7767df5947520cf8bf67267bed00688817fe60a4b82f9c17661b0b25eee6a71a365d9314abb
ep_bytes: 558bec51e825000000ff750cff75088d
timestamp: 2007-12-10 04:07:13

Version Info:

0: [No Data]

Backdoor:WinNT/Farfli.B!sys also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.RtkDL.kZ2y
MicroWorld-eScanBackdoor.Farfli.AB
FireEyeGeneric.mg.ead884d6e2ee396f
CAT-QuickHealBackdoor.Farfli
McAfeeFarfli!sys
Cylanceunsafe
ZillyaDownloader.RtkDL.Win32.1795
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 000a76621 )
AlibabaTrojanDownloader:Win32/RtkDL.52ce1b51
K7GWTrojan-Downloader ( 000a76621 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Rootkit.Agent.ad
CyrenW32/Cinmus.E.gen!Eldorado
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Rootkit.Agent.NCK
APEXMalicious
ClamAVWin.Adware.Cinmus-193
KasperskyTrojan-Downloader.Win32.RtkDL.jtp
BitDefenderBackdoor.Farfli.AB
AvastWin32:Hmir-F [Trj]
TencentWin32.Trojan-Downloader.Rtkdl.Cdhl
EmsisoftBackdoor.Farfli.AB (B)
F-SecureTrojan.TR/Rootkit.Gen
DrWebTrojan.StartPage.26350
VIPREBackdoor.Farfli.AB
TrendMicroRTKT_FARFLI.EOJ
McAfee-GW-EditionFarfli!sys
SophosTroj/NTRootK-DX
SentinelOneStatic AI – Suspicious PE
GDataBackdoor.Farfli.AB
JiangminTrojanDownloader.RtkDL.uu
AviraTR/Rootkit.Gen
Antiy-AVLTrojan[Downloader]/Win32.Hmir.gic
XcitiumTrojWare.Win32.TrojanDownloader.Hmir.~JH3@1p6pn9
ArcabitBackdoor.Farfli.AB
ViRobotTrojan.Win.Z.Farfli.22048
ZoneAlarmTrojan-Downloader.Win32.RtkDL.jtp
MicrosoftBackdoor:WinNT/Farfli.B!sys
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Hmir.C89271
ALYacBackdoor.Farfli.AB
MAXmalware (ai score=85)
VBA32BScope.Trojan.NtRootKit
PandaRootkit/Farfli.gen
TrendMicro-HouseCallRTKT_FARFLI.EOJ
RisingAdWare.Win32.Agent.GEN (CLASSIC)
YandexTrojan.GenAsa!pamHnu/p1jM
IkarusVirus.Win32.Hmir
FortinetW32/Farfli.EOJ!tr.dldr
AVGWin32:Hmir-F [Trj]
Cybereasonmalicious.6e2ee3
DeepInstinctMALICIOUS

How to remove Backdoor:WinNT/Farfli.B!sys?

Backdoor:WinNT/Farfli.B!sys removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment