Trojan

Trojan:Win32/Farfli.GKM!MTB removal guide

Malware Removal

The Trojan:Win32/Farfli.GKM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Farfli.GKM!MTB virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • A process created a hidden window
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Trojan:Win32/Farfli.GKM!MTB?


File Info:

crc32: 7AE70CEE
md5: 7e11847f723255967740e4dc7d157ca1
name: 7E11847F723255967740E4DC7D157CA1.mlw
sha1: a13dcba328423713545aa4d024ea3c4f940b97af
sha256: 293bfbb29fdb4b08c7e603550e03460dee935292c9a404527f103b36029d91a6
sha512: 433882b6c629c04db6b6298996879bd275f286794a1e7253649abd8232b9aa1e618782a08e0c155c62e16ad466cd7b465b7991da78c5dad567e6719d10bcee55
ssdeep: 12288:0nO4RBBAzh99arYVe81336ak1wj0pl0YnLq9njH9PD2mB4n1fca:w5RYzT9arYs8pe1wInCB4nBca
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1998
InternalName: MyFormView
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: MyFormView Application
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: MyFormView MFC Application
OriginalFilename: MyFormView.EXE
Translation: 0x0409 0x04b0

Trojan:Win32/Farfli.GKM!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
ALYacGen:Variant.Midie.84958
CylanceUnsafe
ZillyaTrojan.Antavmu.Win32.13929
CrowdStrikewin/malicious_confidence_90% (W)
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Farfli.BLH
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Antavmu.asrk
BitDefenderGen:Variant.Midie.84958
MicroWorld-eScanGen:Variant.Midie.84958
TencentWin32.Trojan.Geral.Aiib
Ad-AwareGen:Variant.Midie.84958
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.hh
FireEyeGen:Variant.Midie.84958
EmsisoftGen:Variant.Midie.84958 (B)
JiangminBackdoor.Generic.bshw
AviraTR/AD.Farfli.avuwq
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftTrojan:Win32/Farfli.GKM!MTB
GDataGen:Variant.Midie.84958
AhnLab-V3Trojan/Win.Agent.R417294
McAfeeRDN/Generic.grp
MAXmalware (ai score=81)
VBA32BScope.Trojan.Skeeyah
MalwarebytesMalware.AI.4281212056
YandexTrojan.Antavmu!rMbbS28apnc
AVGWin32:Trojan-gen

How to remove Trojan:Win32/Farfli.GKM!MTB?

Trojan:Win32/Farfli.GKM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment