Trojan

About “TrojanDownloader:Win32/Farfli.F!rfn” infection

Malware Removal

The TrojanDownloader:Win32/Farfli.F!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Farfli.F!rfn virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDownloader:Win32/Farfli.F!rfn?


File Info:

crc32: E427110D
md5: ec0bf99805e83e876c584dc90f2753a8
name: EC0BF99805E83E876C584DC90F2753A8.mlw
sha1: 93d50bcc2facfe6b56f2934bb58fe22a29a77dd3
sha256: de8ad22da438be43fe1a67644219591c32751449cd28f0df24c70f6ea28b4a01
sha512: d2bb0cd8170e1e6f6fa1c68dfdca9781199450e0670ee3f1e21e9d0e2492a457c09d7c95dd9eab3cc3e790541d7ddaaf4e04b3a09e7753e72b75cb2e03d74126
ssdeep: 1536:Pb7b871wamWqAr46eyaRcajd0e/krMbyYDi0AhQXhmcJfd5mlj4QyXG4ZhgkahQ:DsZjmg46laPpznmOXp1oaWMWkIzpXy
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

TrojanDownloader:Win32/Farfli.F!rfn also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CGME
FireEyeGeneric.mg.ec0bf99805e83e87
CAT-QuickHealBackdoor.Farfli
ALYacTrojan.Agent.CGME
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 004f30281 )
BitDefenderTrojan.Agent.CGME
K7GWTrojan-Downloader ( 004f30281 )
CrowdStrikewin/malicious_confidence_60% (D)
BaiduWin32.Trojan-Downloader.Agent.bh
CyrenW32/Trojan.IM1.gen!Eldorado
SymantecBackdoor.Trojan
TrendMicro-HouseCallBKDR_FARFLI_GK130005.UVPM
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-6443182-0
KasperskyBackdoor.Win32.Farfli.akkm
NANO-AntivirusTrojan.Win32.Crypted.eejteg
AegisLabTrojan.Win32.Farfli.m!c
RisingBackdoor.Farfli!8.B4 (CLOUD)
Ad-AwareTrojan.Agent.CGME
EmsisoftTrojan.Agent.CGME (B)
F-SecureBackdoor.BDS/Backdoor.Gen7
DrWebBackDoor.PcClient.6543
ZillyaBackdoor.Farfli.Win32.5074
TrendMicroBKDR_FARFLI_GK130005.UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosMal/Generic-S (PUA)
IkarusTrojan-Downloader.Win32.Farfli
JiangminBackdoor.Farfli.amp
AviraBDS/Backdoor.Gen7
eGambitUnsafe.AI_Score_67%
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Farfli
MicrosoftTrojanDownloader:Win32/Farfli.F!rfn
ArcabitTrojan.Agent.CGME
ZoneAlarmBackdoor.Win32.Farfli.akkm
GDataTrojan.Agent.CGME
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Farfli.C2252330
McAfeeArtemis!EC0BF99805E8
VBA32Backdoor.Farfli
MalwarebytesMalware.AI.4067007542
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.CMN
TencentMalware.Win32.Gencirc.10b6d714
YandexTrojan.GenAsa!zssa2zQEwFQ
SentinelOneStatic AI – Malicious PE
FortinetW32/Agent.CGT!tr
BitDefenderThetaGen:NN.ZexaF.34804.gmIfaG2PwygH
AVGWin32:Malware-gen
Cybereasonmalicious.805e83
Paloaltogeneric.ml
Qihoo-360HEUR/QVM11.1.07A9.Malware.Gen

How to remove TrojanDownloader:Win32/Farfli.F!rfn?

TrojanDownloader:Win32/Farfli.F!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment