Malware

How to remove “Win32/Farfli.CMI”?

Malware Removal

The Win32/Farfli.CMI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Farfli.CMI virus can do?

  • Executable code extraction
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Farfli.CMI?


File Info:

crc32: A1D1F0D6
md5: 4fd6d4e61d9ad780dee97b087495dcf5
name: sys1.exe
sha1: 8a29797d1326bbfd5b0800323c3eaa95cedf23db
sha256: 4befc5c8aed2db9500c64e44cf51f7c268f253849a3f576a9023447be3acbdff
sha512: 39a6aeba7c2156d8da2ec4264046add4a76b2c628920327408b982402dad4f925ad1360c9c2dedcc8bacadbe0b525c454951b8cd97b3763c621e265dac58c181
ssdeep: 6144:Gntax2N5AtlFq4Xm5g+CM90dQ2DD6Dswrueeb3xBG3Gp1ZbeX:Gn22NkFq4UHp0mUDzPeu3oX
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Farfli.CMI also known as:

MicroWorld-eScanGen:Heur.Mint.Zard.30
FireEyeGeneric.mg.4fd6d4e61d9ad780
McAfeeArtemis!4FD6D4E61D9A
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005413491 )
BitDefenderGen:Heur.Mint.Zard.30
K7GWTrojan ( 005413491 )
Cybereasonmalicious.61d9ad
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Gh0stRAT-6991184-0
GDataGen:Heur.Mint.Zard.30
KasperskyBackdoor.Win32.Farfli.brvd
NANO-AntivirusTrojan.Win32.DeepScan.fkadkp
RisingMalware.Heuristic!ET#80% (RDMK:cmRtazowN2dJBY4FvARsxMqoXFYo)
Endgamemalicious (moderate confidence)
EmsisoftGen:Heur.Mint.Zard.30 (B)
ComodoBackdoor.Win32.Farfli.CJT@7jjkro
DrWebTrojan.DownLoader27.15157
ZillyaBackdoor.Farfli.Win32.8144
TrendMicroBackdoor.Win32.ZEGOST.SMUKQ
McAfee-GW-EditionGenericRXGP-MV!0FC94B9E1671
SophosTroj/AutoG-EK
IkarusVirus.Win32.CeeInject
JiangminBackdoor.Farfli.che
AviraHEUR/AGEN.1131541
MAXmalware (ai score=85)
Antiy-AVLTrojan[Backdoor]/Win32.Farfli
ArcabitTrojan.Mint.Zard.30
SUPERAntiSpywareTrojan.Agent/Gen-FraudPack
ZoneAlarmBackdoor.Win32.Farfli.brvd
MicrosoftBackdoor:Win32/Zegost.AD
VBA32Backdoor.Farfli
ALYacGen:Heur.Mint.Zard.30
Ad-AwareGen:Heur.Mint.Zard.30
PandaTrj/CI.A
ZonerTrojan.Win32.80250
ESET-NOD32a variant of Win32/Farfli.CMI
TrendMicro-HouseCallBackdoor.Win32.ZEGOST.SMUKQ
TencentWin32.Backdoor.Farfli.Pikk
eGambitUnsafe.AI_Score_99%
FortinetW32/Farfli.CMI!tr
BitDefenderThetaGen:NN.ZexaF.34110.CmGfauH804oj
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Win32/Backdoor.8d9

How to remove Win32/Farfli.CMI?

Win32/Farfli.CMI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment