Malware

Should I remove “Win32/Farfli.DV”?

Malware Removal

The Win32/Farfli.DV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Farfli.DV virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.sousouweb.com

How to determine Win32/Farfli.DV?


File Info:

crc32: 544C25D6
md5: b950ae52cc2c35259284f50b19b5f5e3
name: JJlids.exe
sha1: 392aac91b3b73f7eb630715d79165fee6ff63ae0
sha256: 474b630da6530cf31a58ca0b9bda7cda9ac68aa171069abb6c5c0a81417230a5
sha512: 6446cf25f4ff7f6f6a6fe603d2d8e479bcd5c3379ff7cde062af1891350bd36f20d7906cbc70191c054fa88a4ff5d85090a523c0b0bb21de469084cf681d41d1
ssdeep: 1536:dxW8HkfzJF19PpHR77j6aer4VUIRbDoUl4nouy8:uskX3X7eaer4V93o4wout
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Farfli.DV also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.b950ae52cc2c3525
McAfeeArtemis!B950AE52CC2C
CylanceUnsafe
ZillyaTrojan.Farfli.Win32.35078
AegisLabTrojan.Win32.Farfli.4!c
SangforMalware
K7AntiVirusTrojan ( 0051a9ba1 )
BitDefenderDropped:Trojan.GenericKD.42804943
K7GWTrojan ( 0051a9ba1 )
Cybereasonmalicious.2cc2c3
Invinceaheuristic
F-ProtW32/Backdoor.AE.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Farfli.gen
AlibabaBackdoor:Win32/Zegost.546a155d
NANO-AntivirusTrojan.Win32.KillProc.ctgocl
MicroWorld-eScanDropped:Trojan.GenericKD.42804943
RisingBackdoor.Farfli!1.64A3 (CLOUD)
Ad-AwareDropped:Trojan.GenericKD.42804943
ComodoTrojWare.Win32.Farfli.LK@4pmigc
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebTrojan.KillProc.22090
VIPRETrojan-Dropper.Win32.Farfli.e (v)
FortinetW32/Magania.IKHG!tr
SophosTroj/Zegost-O
IkarusBackdoor.Win32.FirstInj
CyrenW32/OnlineGames.HM.gen!Eldorado
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=80)
ArcabitTrojan.Generic.D28D26CF
ZoneAlarmHEUR:Trojan.Win32.Farfli.gen
MicrosoftBackdoor:Win32/Zegost.BZ
AhnLab-V3Trojan/Win32.Farfli.C3859465
BitDefenderThetaAI:Packer.74124AB91F
ALYacDropped:Trojan.GenericKD.42804943
VBA32BScope.Trojan.Downloader
ESET-NOD32a variant of Win32/Farfli.DV
TencentMalware.Win32.Gencirc.10b8ab0b
YandexTrojan.Farfli!gdFo88Gn8ss
SentinelOneDFI – Malicious PE
eGambitTrojan.Generic
GDataDropped:Trojan.GenericKD.42804943
AVGWin32:Farfli-AX [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Farfli.DV?

Win32/Farfli.DV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment