Trojan

About “Trojan:Win32/Farfli.ASDC!MTB” infection

Malware Removal

The Trojan:Win32/Farfli.ASDC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Farfli.ASDC!MTB virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Farfli.ASDC!MTB?


File Info:

name: 1F0850D0D53331C6A980.mlw
path: /opt/CAPEv2/storage/binaries/f367cee237eef2f0adf728f726b72bb32693ef627d9c2a49d7316141e8bb6563
crc32: 163D5230
md5: 1f0850d0d53331c6a98065e5a3043adb
sha1: f73d4909f9139295e9753c219f4f426d49dd6318
sha256: f367cee237eef2f0adf728f726b72bb32693ef627d9c2a49d7316141e8bb6563
sha512: 8f780673901b13581e7029aa5cb247d955cd7179079c473bde4989a8a500001b111da19e7a6e5d6b636e5eaa4f4a6116b1776945c09b90de248f8c33b208ddf2
ssdeep: 768:3Er7XR1M6t6FikUE58ozVOB+6QcXn0cE5Y18BtrEZJjuSkwFOBezksAMC6Hh4:3EXXM2HEhzVWKtrEZFxFOBLpMC6H
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1DF331A31EA12C0F1EC9A0334B9BF6BA75D6C6C35279C51D37B93165E18A46E2B938313
sha3_384: d81f0dc951688e118d6e9f7a16786fe4b2e22e2dae62eb189001cdaced07b4f6022b58b5270ae3c93753413145ca970c
ep_bytes: 8bff558bec837d0c017505e82b040000
timestamp: 2023-06-13 11:52:46

Version Info:

Comments:
CompanyName:
FileDescription: Install
FileVersion: 1, 0, 0, 1
InternalName: Install
LegalCopyright: 版权所有(C) 2020
LegalTrademarks:
OriginalFilename: Install.dat
PrivateBuild:
ProductName: Install
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0804 0x04b0

Trojan:Win32/Farfli.ASDC!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.354722
FireEyeGeneric.mg.1f0850d0d53331c6
CAT-QuickHealTrojan.GenericPMF.S30268626
SkyhighBehavesLike.Win32.Injector.qh
McAfeeArtemis!1F0850D0D533
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Generic.Win32.1748382
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005a71001 )
K7AntiVirusTrojan ( 005a71001 )
BitDefenderThetaGen:NN.ZedlaF.36744.du8@aehB!Xhj
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Farfli.DDV
APEXMalicious
ClamAVWin.Malware.Farfli-9832713-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Lazy.354722
NANO-AntivirusTrojan.Win32.Farfli.jwvqny
SUPERAntiSpywareTrojan.Agent/Gen-Bulz
AvastWin32:RATX-gen [Trj]
TencentTrojan.Win32.Farfli.he
EmsisoftGen:Variant.Lazy.354722 (B)
F-SecureHeuristic.HEUR/AGEN.1364636
VIPREGen:Variant.Lazy.354722
TrendMicroTROJ_GEN.R011C0DB824
SophosTroj/Farfli-EU
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=80)
GDataWin32.Trojan.PSE.1O07MBS
JiangminTrojan.Generic.hqzkn
GoogleDetected
AviraHEUR/AGEN.1364636
VaristW32/Farfli.JP.gen!Eldorado
Antiy-AVLTrojan/Win32.Farfli.ddv
ArcabitTrojan.Lazy.D569A2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Farfli.ASDC!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R587524
VBA32Trojan.Mamson
ALYacGen:Variant.Lazy.354722
TACHYONTrojan/W32.Agent.52224.AWW
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R011C0DB824
RisingBackdoor.Gh0st!1.D1DA (CLASSIC)
IkarusTrojan.Win32.Farfli
FortinetW32/Bulz.104A!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Farfli.ASDC!MTB?

Trojan:Win32/Farfli.ASDC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment