Backdoor Trojan

Trojan.FunnyDreamBackdoor.A removal tips

Malware Removal

The Trojan.FunnyDreamBackdoor.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.FunnyDreamBackdoor.A virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.FunnyDreamBackdoor.A?


File Info:

name: 3DB71A32BEBE09BF2544.mlw
path: /opt/CAPEv2/storage/binaries/5e90afbdfb63110fa3c9cdd79ef474852996a895a6bad66a663e2ccc51dd339b
crc32: 26DA44D1
md5: 3db71a32bebe09bf25442766ceca5ddc
sha1: c426641b2e8d155a9cbc4c50730923ef446ba45b
sha256: 5e90afbdfb63110fa3c9cdd79ef474852996a895a6bad66a663e2ccc51dd339b
sha512: 9152a9e6be6a63e3a28c3d4ebfa2675f32a9b17be054966c6c8609ff7ecacb7902d5db4409f6c6b06a0facc74ccab63a7615b0afd6264105b410acb9b28263b0
ssdeep: 3072:KEGAnO9M4t2VMWlJ+258ZrQxt6u9iwfKPD/U5/oXE9ssZWs:dFO2llLI8xtawfKA5/2s
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1AF047D02B540C1B6D67F193C44B9EBB25A3F78344B68DDD773848E2A5DA01C0AB357AB
sha3_384: 25284bc04abb79db50de9dc0594a36c74f6ecfa1c52110ca3ed72d8ad86d6406c25f36efbeb626e2a2279171b60fe2c6
ep_bytes: 558bec837d0c017505e828040000ff75
timestamp: 2019-05-29 08:01:37

Version Info:

0: [No Data]

Trojan.FunnyDreamBackdoor.A also known as:

BkavW32.Common.F5BA46B5
LionicTrojan.Win32.APosT.4!c
Elasticmalicious (high confidence)
DrWebBackDoor.Farfli.134
MicroWorld-eScanTrojan.FunnyDreamBackdoor.A
FireEyeGeneric.mg.3db71a32bebe09bf
SkyhighBehavesLike.Win32.NetLoader.ch
McAfeeGenericRXIL-EI!3DB71A32BEBE
Cylanceunsafe
ZillyaTrojan.Farfli.Win32.33334
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/APosT.dd10de3a
K7GWTrojan ( 005679ee1 )
K7AntiVirusTrojan ( 005679ee1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Farfli.CTW
CynetMalicious (score: 100)
KasperskyTrojan.Win32.APosT.jjy
BitDefenderTrojan.FunnyDreamBackdoor.A
NANO-AntivirusTrojan.Win32.APosT.gcnulx
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.115d4ea6
TACHYONTrojan/W32.APosT.173568.B
EmsisoftTrojan.FunnyDreamBackdoor.A (B)
F-SecureTrojan.TR/Farfli.pyvol
VIPRETrojan.FunnyDreamBackdoor.A
TrendMicroTROJ_GIP.ZBHC-A
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.APosT.sl
WebrootW32.Trojan.Gen
VaristW32/Apost.A.gen!Eldorado
AviraTR/Farfli.pyvol
Antiy-AVLTrojan/Win32.Farfli
KingsoftWin32.Trojan.APosT.jjy
XcitiumMalware@#2tu042k17piw9
ArcabitTrojan.FunnyDreamBackdoor.A
ViRobotTrojan.Win32.S.Agent.173568.GJ
ZoneAlarmTrojan.Win32.APosT.jjy
GDataTrojan.FunnyDreamBackdoor.A
GoogleDetected
AhnLab-V3Backdoor/Win32.Agent.R355870
ALYacTrojan.APosT.gen
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Zegost
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GIP.ZBHC-A
RisingBackdoor.FunnyDream!1.D086 (CLASSIC)
IkarusTrojan.Win32.Farfli
MaxSecureTrojan.Malware.9064818.susgen
FortinetW32/Farfli.CRQ!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Trojan.FunnyDreamBackdoor.A?

Trojan.FunnyDreamBackdoor.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment