Backdoor

Should I remove “UDS:Backdoor.Win32.Farfli.cnvo”?

Malware Removal

The UDS:Backdoor.Win32.Farfli.cnvo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Backdoor.Win32.Farfli.cnvo virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Uses Windows utilities for basic functionality
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to disable UAC
  • Disables Windows firewall
  • Attempts to modify UAC prompt behavior
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine UDS:Backdoor.Win32.Farfli.cnvo?


File Info:

name: 7B781A2067AED69191F8.mlw
path: /opt/CAPEv2/storage/binaries/7802d06b8c80d4cf00e3521a0ffb4a01b43a77ecb41948fbb542e3741e1b286d
crc32: F48DB03C
md5: 7b781a2067aed69191f8361e164d9c62
sha1: 74f70838cb68ee054f77fac5c831956cd554a403
sha256: 7802d06b8c80d4cf00e3521a0ffb4a01b43a77ecb41948fbb542e3741e1b286d
sha512: 5a4709d2e8df1ffa5d59c9fc793713fbe8f1b3e460377f04e6a816756e4e90b4dca82dbfeee76155fa5a10b9c6eca0f53a91ebf5bf4ef0d748bc7a0e11278994
ssdeep: 49152:/bWA/+nRZu0X2qrv0ONJkpO0TjGhRA2yz/KqEq2G1dA0MgOjM7:/bWDZu0mQsOwppTqhRAvKqEq2G1dbnO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A85EFDB4D0446F3CB4DF83004A373BC172FA83E6BD70E1D998BAD999B7988D9085646
sha3_384: 2babfae92fa5e451609c7133b3688d86715eeccfce54ddc78eb59f92e151f7477187d7d8667d3aaf263fbfa307af4a6e
ep_bytes: 60be00c047008dbe0050f8ff57eb0b90
timestamp: 2023-11-08 14:25:55

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft OneDrive
InternalName: Client Application
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: OneDrive.exe
ProductName: Microsoft OneDrive
FileVersion: 21.220.1024.0005
ProductVersion: 21.220.1024.0005
SpecialBuild: b/build/2c205c5c-e050-0ffd-f7d0-63786687edbc
Translation: 0x0409 0x04b0

UDS:Backdoor.Win32.Farfli.cnvo also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Heur.Mint.Zard.40
FireEyeGen:Heur.Mint.Zard.40
SkyhighBehavesLike.Win32.Generic.tc
McAfeeArtemis!7B781A2067AE
VIPREGen:Heur.Mint.Zard.40
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Heur.Mint.Zard.40
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
KasperskyUDS:Backdoor.Win32.Farfli.cnvo
EmsisoftGen:Heur.Mint.Zard.40 (B)
F-SecureHeuristic.HEUR/AGEN.1342747
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.Disabler
VaristW32/Trojan.CLL.gen!Eldorado
AviraHEUR/AGEN.1342747
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Mint.Zard.40
ZoneAlarmVHO:Backdoor.Win32.Agent.gen
GDataWin32.Application.PSE.10ODIJ9
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2717505
BitDefenderThetaGen:NN.ZexaF.36792.VnKfa8F3EOkj
ALYacGen:Heur.Mint.Zard.40
DeepInstinctMALICIOUS
VBA32Win32.Trojan.Dropper.Heur
Cylanceunsafe
YandexTrojan.GenAsa!ReEpzfU58ew
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Dh-A [Heur]
AvastWin32:Dh-A [Heur]

How to remove UDS:Backdoor.Win32.Farfli.cnvo?

UDS:Backdoor.Win32.Farfli.cnvo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment