Trojan

Trojan-Downloader.Win64.Farfli.ey malicious file

Malware Removal

The Trojan-Downloader.Win64.Farfli.ey is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win64.Farfli.ey virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan-Downloader.Win64.Farfli.ey?


File Info:

name: 9FBF452020A29113F832.mlw
path: /opt/CAPEv2/storage/binaries/aa531cab75741c8da9d7d86c3e2d9b15aa322178f332ffa0edc92a2603b4edf5
crc32: 2B2F1719
md5: 9fbf452020a29113f8321eac91916b88
sha1: 1b6af4e2a9bec36fd53cb601f917bb371704f756
sha256: aa531cab75741c8da9d7d86c3e2d9b15aa322178f332ffa0edc92a2603b4edf5
sha512: 1be7e5220e7b40f6ac91ca39760527c65f64309b87f166be098b30291a89c815407cdde533f92598f58c09a31701f958adb20495bf68906905d7856ef2621f22
ssdeep: 6144:PP37OsPgJz3JvIJt6X6qwOdqwO8Cmj0qUDrLe6Ckos6:PjO4gz3l64gmj0qUDI
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T189C4A496B15050AADC6BF1B2E82FE972B4323DDA4730D34A12537B1B8BF36515837B12
sha3_384: e2ac98d56df739739d147379477941a7a8c1f5d56eeae400a9dcbed88d9d7c75595b6ddcf3ba99fc200170b0538a1daa
ep_bytes: 4883ec28e877890000e8120000004883
timestamp: 2021-11-27 09:24:36

Version Info:

CompanyName: Tencent
FileDescription: 腾讯视频
FileVersion: 11.32.2015.0
InternalName: QQLive
LegalCopyright: Copyright (C) 1998 - 2021 Tencent. All Rights Reserved
OriginalFilename: QQLive.exe
ProductName: 腾讯视频
ProductVersion: 11.32.2015.0
Translation: 0x0804 0x04b0

Trojan-Downloader.Win64.Farfli.ey also known as:

LionicTrojan.Win64.Farfli.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38134990
FireEyeGeneric.mg.9fbf452020a29113
CAT-QuickHealTrojanDownloader.Win64
ALYacTrojan.GenericKD.38134990
CylanceUnsafe
ZillyaDownloader.Farfli.Win64.34
K7AntiVirusTrojan-Downloader ( 0058a0ee1 )
AlibabaTrojanDownloader:Win64/Farfli.0e930242
K7GWTrojan-Downloader ( 0058a0ee1 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/TrojanDownloader.Agent.ML
TrendMicro-HouseCallTROJ_GEN.R002C0PL121
KasperskyTrojan-Downloader.Win64.Farfli.ey
BitDefenderTrojan.GenericKD.38134990
AvastWin64:Trojan-gen
TencentWin64.Trojan-downloader.Agent.Hykd
Ad-AwareTrojan.GenericKD.38134990
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PL121
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftTrojan.GenericKD.38134990 (B)
JiangminTrojanDownloader.Farfli.aw
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.34E0A30
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GridinsoftRansom.Win64.Sabsik.sa
GDataTrojan.GenericKD.38134990
McAfeeRDN/Generic Downloader.x
VBA32TrojanDownloader.Win64.Farfli
MalwarebytesBackdoor.Farfli
RisingDownloader.Agent!1.D154 (CLASSIC)
IkarusTrojan.Agent4
FortinetW64/Agent.ML!tr.dldr
AVGWin64:Trojan-gen
PandaTrj/CI.A

How to remove Trojan-Downloader.Win64.Farfli.ey?

Trojan-Downloader.Win64.Farfli.ey removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment