Malware

About “Win32/Farfli.CXE” infection

Malware Removal

The Win32/Farfli.CXE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Farfli.CXE virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/Farfli.CXE?


File Info:

crc32: 9CCE7D02
md5: 5ab3fc062060e9c79378820653da9133
name: 5AB3FC062060E9C79378820653DA9133.mlw
sha1: 9ee468e3946fac9a41a7cd155d9fa68458dcdaf8
sha256: 797004de63aae483457083e9ac7df94b8de6b2f168b9c546a149aa4b3cf72133
sha512: c6b1a4636d8ef4ade0dc024702e7c05c2bc876189b8a5d47724d557b850de4b2e0f31bcc56e77257c7286780cbd4fabd5f7429ae2507401c49d1c4f0cd7b6713
ssdeep: 1536:rDdBjrLDxGax9ypf/0vBRBt9861yKRp8sQ/zLcT10:d9LFGaCpMXBXJCh/UT10
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2005
InternalName: Style
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: Style x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: Style Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: Style.EXE
Translation: 0x0804 0x04b0

Win32/Farfli.CXE also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.44014
CynetMalicious (score: 100)
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (D)
Cybereasonmalicious.3946fa
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Farfli.CXE
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Ardamax.cojase
SophosML/PE-A
ComodoTrojWare.Win32.Magania.A@5wdy5u
BitDefenderThetaGen:NN.ZexaF.34722.fr3@aqlXtxeb
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroBackdoor.Win32.ZEGOST.SMAL02
McAfee-GW-EditionGeneric Malware.dq
FireEyeGeneric.mg.5ab3fc062060e9c7
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Farfli.eak
Antiy-AVLTrojan/Generic.ASMalwS.30F12ED
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftTrojan:Win32/Farfli.DSK!MTB
GridinsoftMalware.Win32.Gen.bot!se3406
AhnLab-V3Malware/Win32.RL_Backdoor.R353637
McAfeeGeneric Malware.dq
VBA32BScope.Trojan.Fsysna
TrendMicro-HouseCallBackdoor.Win32.ZEGOST.SMAL02
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazoyOtB/zFGVv2kK/67AVX1j)
YandexTrojan.GenAsa!h5z7SD0BGl0
IkarusBackdoor.Win32.Bifrose
FortinetW32/Generic.AC.235451!tr
AVGWin32:Evo-gen [Susp]

How to remove Win32/Farfli.CXE?

Win32/Farfli.CXE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment