Trojan

What is “TrojanDownloader:Win32/Farfli.F!bit”?

Malware Removal

The TrojanDownloader:Win32/Farfli.F!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Farfli.F!bit virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

hk.hackjerry.xyz

How to determine TrojanDownloader:Win32/Farfli.F!bit?


File Info:

crc32: F15019B4
md5: 7ca7e8d55671b6af337baa0f3d223f9b
name: SQLServar.exe
sha1: ed931422a8b2912139a687da76a8885c8a453dfb
sha256: cff50f69352e4ce2efd77a2fc97e2810842d81bb0d5c230ee67903b1632dd0d0
sha512: 752b854cc267b42d30fc75de72078164a4d525e7d732276c81b41709c169ef3ce865b9192f10b4ee0b99b60ad756fd1f19b5f2878b1c86cc88653e17f5c4be92
ssdeep: 768:bzGUa7rgOUttLzehCQb9INCOsOX0dKUkyCHB5EINQwu0RpQcFCOJ7q7T7:3GU2rBUvehCQaNtkd+y0B5EINQwuIQB
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (c) 2000-2012 Cortado AG
InternalName: TPView
FileVersion: 8,8,821,1
CompanyName: Cortado AG
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: ThinPrint Viewture
SpecialBuild:
ProductVersion: 8,8,821,1
FileDescription: ThinPrint Previewer
OriginalFilename: tpview.dll
Translation: 0x0409 0x04b0

TrojanDownloader:Win32/Farfli.F!bit also known as:

MicroWorld-eScanGen:Variant.Graftor.310855
FireEyeGeneric.mg.7ca7e8d55671b6af
CAT-QuickHealTrojan.MauvaiseRI.S5244830
Qihoo-360Win32/Backdoor.fdc
McAfeeArtemis!7CA7E8D55671
AegisLabTrojan.Win32.Farfli.m!c
SangforMalware
K7AntiVirusTrojan-Downloader ( 004f95c91 )
BitDefenderGen:Variant.Graftor.310855
K7GWTrojan-Downloader ( 004f95c91 )
Cybereasonmalicious.55671b
TrendMicroTROJ_GEN.R002C0CC520
BitDefenderThetaGen:NN.ZexaE.34098.cmKfaqNlVmhj
CyrenW32/Trojan.LTHS-3470
SymantecSMG.Heur!gen
BaiduWin32.Trojan-Downloader.Agent.bh
TrendMicro-HouseCallTROJ_GEN.R002C0CC520
Paloaltogeneric.ml
GDataGen:Variant.Graftor.310855
KasperskyBackdoor.Win32.Farfli.anzu
AlibabaBackdoor:Win32/Zlob.180910
NANO-AntivirusTrojan.Win32.Farfli.egqihz
ViRobotTrojan.Win32.Z.Farfli.35840
TencentWin32.Backdoor.Farfli.Akzf
Ad-AwareGen:Variant.Graftor.310855
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Agent.FACA@6tb4lj
F-SecureHeuristic.HEUR/AGEN.1006826
DrWebBackDoor.PcClient.6543
Invinceaheuristic
McAfee-GW-EditionGenericRXAP-JG!B6BEA55C1D7A
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Graftor.310855 (B)
APEXMalicious
JiangminBackdoor.Farfli.arb
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1006826
Antiy-AVLTrojan[Backdoor]/Win32.Farfli
Endgamemalicious (moderate confidence)
ArcabitTrojan.Graftor.D4BE47
ZoneAlarmBackdoor.Win32.Farfli.anzu
MicrosoftTrojanDownloader:Win32/Farfli.F!bit
TACHYONBackdoor/W32.Farfli.77824.K
AhnLab-V3Backdoor/Win32.RL_Farfli.R294746
VBA32BScope.Backdoor.Farfli
ALYacGen:Variant.Graftor.310855
MAXmalware (ai score=86)
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.CAY
RisingBackdoor.Farfli!8.B4 (CLOUD)
IkarusTrojan-Downloader.Win32.Agent
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.CGT!tr
AVGFileRepMalware
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (W)

How to remove TrojanDownloader:Win32/Farfli.F!bit?

TrojanDownloader:Win32/Farfli.F!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment