Trojan

Trojan:Win32/Farfli.BAU!MTB information

Malware Removal

The Trojan:Win32/Farfli.BAU!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Farfli.BAU!MTB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Farfli.BAU!MTB?


File Info:

name: 668ED606DD2E389345C4.mlw
path: /opt/CAPEv2/storage/binaries/4e4e0cd1e1688506082b10fe11591c78405dbe43a603b3f9c006920098b5b97b
crc32: 9217EBF0
md5: 668ed606dd2e389345c4b829b325a6cc
sha1: a4c4ddad552ff95be069b6e5e37c85052b6e8d25
sha256: 4e4e0cd1e1688506082b10fe11591c78405dbe43a603b3f9c006920098b5b97b
sha512: b1c0cfde9e05ec6c20dd4f35d1d5d047b890a4476ee60ce8ecb36377f60d4a5be1954f260d10716748649a6224ef3797b9b5594b893e7ee40ffa63eef9ed457c
ssdeep: 6144:1qkPAv0Y381qQa/sV3s73X8ROVXQ4vMROHN/hgCqnzpQ:PAsYqPa/RTX8RsUm+Cq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T120C47B2076408075E365073155EAEAF00A79AD3A13A9A1CFF7B83A396E711D34B3725F
sha3_384: 51342ef080457cdc320d650c3ee0032e31a5ad0b32f2c79cf10a7d7eb3da4887c7c74a2cf7f8c69249d6b1b33d7a75eb
ep_bytes: 00908a460323d18847038a4602884702
timestamp: 2013-10-03 12:02:59

Version Info:

0: [No Data]

Trojan:Win32/Farfli.BAU!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Wecod.4!c
MicroWorld-eScanGen:Variant.Mikey.114265
FireEyeGeneric.mg.668ed606dd2e3893
ALYacGen:Variant.Mikey.114265
MalwarebytesCardSpy.Spyware.Stealer.DDS
VIPREGen:Variant.Mikey.114265
SangforVirus.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Urelas.e419c8aa
K7GWRiskware ( 00584baa1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaE.36196.KiZ@aGOufEg
VirITTrojan.Win32.Generic.DPE
CyrenW32/Urelas.AQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.MITBSPB
APEXMalicious
ClamAVWin.Malware.Wacatac-9770172-0
KasperskyUDS:Trojan.Win32.Wecod.ajbo
BitDefenderGen:Variant.Mikey.114265
AvastWin32:Malware-gen
TencentTrojan.Win32.CardSpy.16000130
TACHYONTrojan/W32.Agent.589824.WH
SophosMal/Generic-S
BaiduWin32.Trojan.Urelas.d
F-SecureHeuristic.HEUR/AGEN.1300631
ZillyaTrojan.Wecod.Win32.6923
TrendMicroTROJ_GEN.R03BC0DDJ23
McAfee-GW-EditionBehavesLike.Win32.Generic.ht
EmsisoftGen:Variant.Mikey.114265 (B)
IkarusTrojan-PWS.Banker6
GDataGen:Variant.Mikey.114265
GoogleDetected
Antiy-AVLTrojan/Win32.Wacatac
XcitiumTrojWare.Win32.Rogue.WE@53jbqv
ArcabitTrojan.Mikey.D1BE59
ZoneAlarmUDS:Trojan.Win32.Wecod.ajbo
MicrosoftTrojan:Win32/Farfli.BAU!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R568625
McAfeeGenericRXVU-LW!668ED606DD2E
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DDJ23
RisingSpyware.CardSpy!1.A1A8 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/CardSpy.PRKJ!tr
AVGWin32:Malware-gen
Cybereasonmalicious.6dd2e3
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Farfli.BAU!MTB?

Trojan:Win32/Farfli.BAU!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment