Malware

Win32/Farfli.CUB (file analysis)

Malware Removal

The Win32/Farfli.CUB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Farfli.CUB virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Deletes its original binary from disk
  • Creates a hidden or system file

How to determine Win32/Farfli.CUB?


File Info:

crc32: 627EB987
md5: 7bbdb9b37b1b9f5c0caeccfd800c441d
name: 7BBDB9B37B1B9F5C0CAECCFD800C441D.mlw
sha1: 980c272090046cb2c859fbbf744da1c22c3379c7
sha256: 03b0adc57f85206f7241e5a8d2db58577aa3e73ad0bfe83eea71aaea815b029f
sha512: 5465a4ec4541b52880babe6e4d588c5c24ce3ff51d25bdd0ea228324022fd3115e3d665a579bacb017ff8280050b530599333df5a3ce0e1f8b72fb73b475e08b
ssdeep: 12288:pjYBl4QKj3kEkjeQKji6UfHlf8VETpBe:tYBEzXcQG6UdfGN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Ontrack
FileVersion: 12.0.0.2
CompanyName: Ontrack
Comments: This installation was built with Inno Setup.
ProductName: Ontrackxae EasyRecoveryx2122 Home for Windows
ProductVersion: 12.0.0.2
FileDescription: Ontrack
Translation: 0x0000 0x04b0

Win32/Farfli.CUB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051149f1 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop7.60238
CynetMalicious (score: 100)
ALYacGen:Variant.Ulise.203979
CylanceUnsafe
ZillyaTrojan.Farfli.Win32.33561
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0051149f1 )
Cybereasonmalicious.37b1b9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Farfli.CUB
APEXMalicious
AvastWin32:Downloader-TZT [Trj]
ClamAVWin.Trojan.Farfli-9833024-0
KasperskyBackdoor.Win32.Farfli.brub
BitDefenderGen:Variant.Ulise.203979
NANO-AntivirusTrojan.Win32.Farfli.excnot
MicroWorld-eScanGen:Variant.Ulise.203979
TencentMalware.Win32.Gencirc.10b9cdb8
Ad-AwareGen:Variant.Ulise.203979
SophosML/PE-A + Mal/PdfExDr-B
BitDefenderThetaGen:NN.ZexaF.34758.cz0@aurKR4jP
TrendMicroBKDR_ZEGOST.SM40
FireEyeGeneric.mg.7bbdb9b37b1b9f5c
EmsisoftGen:Variant.Ulise.203979 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Farfli.bog
AviraTR/Crypt.ZPACK.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.23739D3
MicrosoftBackdoor:Win32/Zegost.DE!bit
ArcabitTrojan.Ulise.D31CCB
ZoneAlarmBackdoor.Win32.Farfli.brub
GDataWin32.Backdoor.Farfli.H
TACHYONBackdoor/W32.Farfli.1082880
AhnLab-V3Backdoor/Win32.Zegost.C4342692
McAfeeGenericRXAA-AA!7BBDB9B37B1B
MAXmalware (ai score=87)
VBA32BScope.Trojan.MulDrop
MalwarebytesSpyware.Socelars
TrendMicro-HouseCallBKDR_ZEGOST.SM40
RisingBackdoor.Zegost!1.D4C0 (CLASSIC)
YandexTrojan.GenAsa!0Afm94UHAik
IkarusTrojan.Win32.Farfli
MaxSecureTrojan.Malware.74250093.susgen
FortinetW32/Farfli.CUB!tr
AVGWin32:Downloader-TZT [Trj]

How to remove Win32/Farfli.CUB?

Win32/Farfli.CUB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment