Malware

What is “Win32/Farfli.CGG”?

Malware Removal

The Win32/Farfli.CGG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Farfli.CGG virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Farfli.CGG?


File Info:

name: 14DDA4D5197D0A561C62.mlw
path: /opt/CAPEv2/storage/binaries/332fd2359175ef61b374c105a0fbf93f9916908d45418d34542b490bd1e8aa8b
crc32: A24D9C1F
md5: 14dda4d5197d0a561c629075a344eb44
sha1: eec5d9a3c8449ea92ea5c0e12c927470bc41a070
sha256: 332fd2359175ef61b374c105a0fbf93f9916908d45418d34542b490bd1e8aa8b
sha512: 55d16bfe41c1c35fc4c22f9fbc79ffff579a1f56fc3493d35d21bbe7961c892d3c6b8cea6fbbd884b04f3850c04ab6dedaa5ef33a82772b70f2ec429030406b1
ssdeep: 3072:s+HDVTtkdiAojheSc5ch491vxqHMkumn0lBE4vvaPc5nm7gynXVpXVRzv8RIS:zHR8iAoNbc5+4z4z45nGgyXVS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BF24F16A9C83006BD4514430C1A289E11FBD5D133592397FCFE4BA4B3D7229A9876EFB
sha3_384: 1a537485588e2ae1f77da0fe85744daf8cc55d4d41a105187d39c4a29a513d40397285320f37de24957df9d392d46a59
ep_bytes: 90906aff68e060400068403d40009090
timestamp: 2011-11-19 13:56:45

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows 服务主进程
FileVersion: 6.1.7600.16385
InternalName: svchost.exe
LegalCopyright: Microsoft Corporation. All rights reserved.
OriginalFilename: svchost.exe
ProductName: Microsoft Windows Operating System
ProductVersion: 6.1.7600.16385
Translation: 0x0409 0x04b0

Win32/Farfli.CGG also known as:

BkavW32.AIDetectMalware
AVGWin32:GenMalicious-ION [Trj]
DrWebTrojan.SpyBot.324
MicroWorld-eScanGen:Trojan.Redosdru.!o!.1
FireEyeGeneric.mg.14dda4d5197d0a56
CAT-QuickHealBackDoor.Zegost.BL3
SkyhighBehavesLike.Win32.Generic.dc
McAfeeGenericRXAK-RQ!14DDA4D5197D
Cylanceunsafe
ZillyaTrojan.Dialer.Win32.14191
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0055e3e41 )
K7AntiVirusTrojan ( 0055e3e41 )
BitDefenderThetaGen:NN.ZexaF.36802.nquaaavtB!hj
VirITBackdoor.Win32.Generic.BWHC
SymantecBackdoor.Trojan
Elasticmalicious (high confidence)
ESET-NOD32Win32/Farfli.CGG
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Dialer-5030
KasperskyHEUR:Trojan.Win32.Farfli.gen
BitDefenderGen:Trojan.Redosdru.!o!.1
NANO-AntivirusTrojan.Win32.Scar.csquoe
AvastWin32:GenMalicious-ION [Trj]
TencentHackTool.Win32.Loader.a
EmsisoftGen:Trojan.Redosdru.!o!.1 (B)
F-SecureBackdoor.BDS/Zegost.birna
BaiduWin32.Backdoor.Zegost.a
VIPREGen:Trojan.Redosdru.!o!.1
TrendMicroTROJ_GEN.R03BC0CDE24
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Dialer
GDataGen:Trojan.Redosdru.!o!.1
JiangminTrojan/Generic.wxse
GoogleDetected
AviraBDS/Zegost.birna
Antiy-AVLTrojan/Win32.Dialer.adub
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Agent.PDSB@4q3i1w
ArcabitTrojan.Redosdru.!o!.1
ZoneAlarmHEUR:Trojan.Win32.Farfli.gen
MicrosoftBackdoor:Win32/Farfli!pz
VaristW32/Zegost.BW.gen!Eldorado
AhnLab-V3Trojan/Win32.Dialer.C137708
Acronissuspicious
ALYacGen:Trojan.Redosdru.!o!.1
TACHYONTrojan/W32.Dialer.225280.J
VBA32SScope.Trojan.SvcHorse.01643
MalwarebytesGeneric.Malware.AI.DDS
PandaBck/Hupigon.LNK
TrendMicro-HouseCallTROJ_GEN.R03BC0CDE24
RisingTrojan.Win32.Lebag.b (CLASSIC)
YandexTrojan.GenAsa!+hGyvTXHWU4
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.11374565.susgen
FortinetW32/Farfli.CMY!tr
ZonerTrojan.Win32.30029
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Redosdru.970c8c59

How to remove Win32/Farfli.CGG?

Win32/Farfli.CGG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment