Malware

Win32/Farfli.CWX removal

Malware Removal

The Win32/Farfli.CWX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Farfli.CWX virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Win32/Farfli.CWX?


File Info:

crc32: FB393099
md5: 326abfed4ebbcb19fdc21113f49ca3d5
name: 326ABFED4EBBCB19FDC21113F49CA3D5.mlw
sha1: 810f78f7619b0d4a63dd8efd02da60c45cca6052
sha256: 788cac3b58d5a0749d4d127bfbad7b57fdabbe9ced7060d569be73d5d5a11b28
sha512: 8cdef7428aca9658a68cc2333e208ba7161eed8c4a5fda7287a391ba4879afb8c3db830ef54ac4af108ec3b59e8b8cdd4cd5328bba54cd7edb65f708c30feade
ssdeep: 768:jbz3IhpglwpDEq2m0j6Tf8V4Ie7ZZa3R1fb961vNPrl70JnCJ0uEVN:n4+wpDElm2IAUZZo1fbs1RV0ZCJ0j
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2014
InternalName: Gh0st
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: Gh0st x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: Gh0st Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: Gh0st.EXE
Translation: 0x0804 0x04b0

Win32/Farfli.CWX also known as:

BkavW32.AIDetectVM.malware2
K7AntiVirusTrojan ( 004cc1441 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.8100
MicroWorld-eScanTrojan.CryptRedol.Gen.3
FireEyeGeneric.mg.326abfed4ebbcb19
ALYacTrojan.CryptRedol.Gen.3
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004cc1441 )
Cybereasonmalicious.d4ebbc
CyrenW32/Farfli.BW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Farfli.CWX
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Mikey-9769164-0
KasperskyBackdoor.Win32.Lotok.chd
BitDefenderTrojan.CryptRedol.Gen.3
TencentMalware.Win32.Gencirc.10cde66f
Ad-AwareTrojan.CryptRedol.Gen.3
SophosTroj/AutoG-IQ
BitDefenderThetaAI:Packer.5F77E27D1F
VIPRETrojan.Win32.Generic!BT
InvinceaML/PE-A + Troj/AutoG-IQ
McAfee-GW-EditionGenericRXLV-PA!326ABFED4EBB
EmsisoftTrojan.CryptRedol.Gen.3 (B)
SentinelOneDFI – Suspicious PE
JiangminBackdoor.Lotok.kl
AviraTR/Farfli.xtyzx
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Woreflint.A!cl
ArcabitTrojan.CryptRedol.Gen.3
ZoneAlarmBackdoor.Win32.Lotok.chd
GDataTrojan.CryptRedol.Gen.3
TACHYONBackdoor/W32.Lotok.63488
AhnLab-V3Malware/Win32.Generic.C4158600
McAfeeGenericRXLV-PA!326ABFED4EBB
MAXmalware (ai score=85)
VBA32BScope.Trojan.Wacatac
RisingBackdoor.Lotok!8.111D5 (TFE:4:LPezLtL370H)
YandexTrojan.Farfli!yEqsPUBNLbU
IkarusTrojan.Win32.Farfli
MaxSecureTrojan.Malware.8984491.susgen
FortinetW32/Lotok.CHD!tr.bdr
AVGWin32:Trojan-gen
Qihoo-360Win32/Backdoor.4ea

How to remove Win32/Farfli.CWX?

Win32/Farfli.CWX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment