Malware

Win32/Farfli.ATU information

Malware Removal

The Win32/Farfli.ATU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Farfli.ATU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • The following process appear to have been packed with Themida: conime.exe
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

me.scieron.com

How to determine Win32/Farfli.ATU?


File Info:

crc32: B70E4EDA
md5: 50331e4852fec6193ab35d88ffca9d67
name: 50331E4852FEC6193AB35D88FFCA9D67.mlw
sha1: caaad40c0f6173024d52c590468a869b60b0db8c
sha256: 1e18e5a15961805d724cd0fa6626cdfdd54e443542c4501e30534564787056be
sha512: ace82cfcae52c7026e45960d75729821dd0885903d02d84660150f0b3bbfc59a6cb925a3cbbb9303ac21554220b6a58b39697d432a600a39a9b5614c133d9fd0
ssdeep: 24576:uwuIqW8YKxgK5CYchUSy6T0dpCL3dHy6nYlgbq97Q:uwhlKvlPCL3Zy6nLyQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename:
Translation: 0x0804 0x03a8

Win32/Farfli.ATU also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e39b1 )
DrWebBackDoor.Moudoor.4
CynetMalicious (score: 100)
ALYacTrojan.Delf.FareIt.Gen.cH0@ne53M5gb
ZillyaTrojan.Packed.Win32.122893
SangforBackdoor.Win32.Zegost.mtgfy
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaBackdoor:Win32/Zegost.c0187975
K7GWTrojan ( 0055e39b1 )
Cybereasonmalicious.852fec
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Farfli.ATU
APEXMalicious
AvastWin32:Malware-gen
KasperskyBackdoor.Win32.Zegost.mtgfy
BitDefenderTrojan.Delf.FareIt.Gen.cH0@ne53M5gb
NANO-AntivirusTrojan.Win32.MLW.djawwy
MicroWorld-eScanTrojan.Delf.FareIt.Gen.cH0@ne53M5gb
TencentWin32.Trojan.Palevo.Auto
Ad-AwareTrojan.Delf.FareIt.Gen.cH0@ne53M5gb
SophosMal/Generic-S (PUA)
ComodoMalware@#3c8q37nacm2c2
BitDefenderThetaGen:NN.ZelphiF.34266.cH0@ae53M5gb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Worm.tc
FireEyeGeneric.mg.50331e4852fec619
EmsisoftTrojan.Delf.FareIt.Gen.cH0@ne53M5gb (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Zegost.vc
WebrootW32.Trojan.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3394B69
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Delf.FareIt.Gen.EDD34C
GDataTrojan.Delf.FareIt.Gen.cH0@ne53M5gb
AhnLab-V3Trojan/Win32.Gen
McAfeeArtemis!50331E4852FE
MAXmalware (ai score=72)
VBA32TScope.Malware-Cryptor.SB
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.82 (RDML:V9yuYFH+8g29Iy1IyeAIXg)
YandexTrojan.GenAsa!5Bmn2KM0i0M
IkarusDownloader.Delphi
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Farfli.ATU?

Win32/Farfli.ATU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment