Backdoor

UDS:Backdoor.Win32.Farfli removal tips

Malware Removal

The UDS:Backdoor.Win32.Farfli is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Backdoor.Win32.Farfli virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Detects Sandboxie through the presence of a library
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Anomalous binary characteristics

How to determine UDS:Backdoor.Win32.Farfli?


File Info:

crc32: 50B366FD
md5: 30ca6361c8cd0b200b836d8741c559fb
name: 30CA6361C8CD0B200B836D8741C559FB.mlw
sha1: bc23a42819180d8118dc4a3d995bd58a98bfe7bc
sha256: 1bc9fb977d1208740080563508351c992e342c8ffb75e30166cb590c5833db83
sha512: 7de263ffa3befa75fe0d21e1cb198095929bb11115603bcb117e4e38ac3bc7dfe70081e728d8cf650a4e3b477a6a0d3a6b33bf80554b30795f2f4969c929454b
ssdeep: 49152:Vo01lx5On46dT+6qHC3HR+QpeqdIqG2Jz:VjLu46hBqHq+QppVJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: ? Microsoft Corporation. All rights reserved.
InternalName: InterNetCheck.exe
FileVersion: 9.30.9200.20789
CompanyName: Microsoft Corporation
ProductName: Microsoft? DirectX for Windows?
ProductVersion: 9.30.9200.20789
FileDescription: Direct3D HLSL Compiler
OriginalFilename: InterNetCheck.exe
Translation: 0x0804 0x03a8

UDS:Backdoor.Win32.Farfli also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.819180
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMetagen [Malware]
KasperskyUDS:Backdoor.Win32.Farfli
SophosML/PE-A + Mal/VMProtBad-A
BitDefenderThetaGen:NN.ZexaF.34678.0z0@aWbdSvdj
McAfee-GW-EditionBehavesLike.Win32.AutoitDropper.tc
FireEyeGeneric.mg.30ca6361c8cd0b20
MicrosoftBackdoor:Win32/Zegost.L
McAfeeBackDoor-FDOH!30CA6361C8CD
VBA32BScope.Trojan.Download
MalwarebytesMalware.Heuristic.1003
RisingMalware.Heuristic!ET#86% (RDMK:cmRtazo5IR2V5sJ3H9V2upuZrHx8)
SentinelOneStatic AI – Suspicious PE
AVGFileRepMetagen [Malware]

How to remove UDS:Backdoor.Win32.Farfli?

UDS:Backdoor.Win32.Farfli removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment