Home Malware Programs Backdoors Backdoor:Win32/Farfli.AV

Backdoor:Win32/Farfli.AV

Posted: June 25, 2013

Threat Metric

Threat Level: 6/10
Infected PCs: 1,972
First Seen: June 25, 2013
Last Seen: August 28, 2022
OS(es) Affected: Windows

Backdoor:Win32/Farfli.AV is a backdoor Trojan that allows a remote attacker to gain access and control to the infected computer. Backdoor:Win32/Farfli.AV can log keystrokes and steal a victim's confidential information. Backdoor:Win32/Farfli.AV can download other malware threats on the corrupted PC. Backdoor:Win32/Farfli.AV may steal the affected computer user's confidential information by recording his/her usernames and passwords. When installed, Backdoor:Win32/Farfli.AV makes system changes by adding potentially malicious files. Backdoor:Win32/Farfli.AV adds itself to the start menu to ensure it runs automatically every time Windows is started. Backdoor:Win32/Farfli.AV replicates itself as a malicious file. Backdoor:Win32/Farfli.AV attempts to connect to a remote server to receive commands. Backdoor:Win32/Farfli.AV modifies system settings and runs or stops applications.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\XXXXXX7B32C78F\svchsot.exe File name: svchsot.exe
Size: 139.89 MB (139894507 bytes)
MD5: 5a2417a1c607464051ec9e2c0bcad34e
Detection count: 145
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\XXXXXX7B32C78F
Group: Malware file
Last Updated: April 27, 2017
%WINDIR%\XXXXXXE640E383\svchsot.exe File name: svchsot.exe
Size: 200.7 KB (200704 bytes)
MD5: 377e64bc752914e0c1cb5a223d0111f0
Detection count: 101
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\XXXXXXE640E383
Group: Malware file
Last Updated: April 27, 2017
%USERPROFILE%\WINDOWS\XXXXXX494360EE\svchsot.exe File name: svchsot.exe
Size: 536.65 KB (536650 bytes)
MD5: bb2b345cf7534b94b8357273870be8c6
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\WINDOWS\XXXXXX494360EE
Group: Malware file
Last Updated: April 27, 2017
file.exe File name: file.exe
Size: 297.2 KB (297206 bytes)
MD5: db10c94b48e4838b800d7a386b9836fc
Detection count: 74
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 6, 2020
%USERPROFILE%\WINDOWS\718032F4\svchsot.exe File name: svchsot.exe
Size: 844.8 KB (844800 bytes)
MD5: c5d017bb110b1ea9f91d77cb8eae9376
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\WINDOWS\718032F4
Group: Malware file
Last Updated: April 27, 2017
%WINDIR%\XXXXXX579E5A5B VVVVVVrr2unw==\svchsot.exe File name: svchsot.exe
Size: 315.39 KB (315392 bytes)
MD5: e79a87fba2dd859b02d9294495b92f13
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\XXXXXX579E5A5B VVVVVVrr2unw==
Group: Malware file
Last Updated: September 14, 2017
%WINDIR%\B4F1E958\svchsot.exe File name: svchsot.exe
Size: 81.92 KB (81920 bytes)
MD5: 25c9e88240fde5cdb12ded7823e143ec
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\B4F1E958
Group: Malware file
Last Updated: April 27, 2017
%WINDIR%\915B0A16\svchsot.exe File name: svchsot.exe
Size: 307.2 KB (307200 bytes)
MD5: dfcb9a0fe689528644d8ec2fc79e0d8b
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\915B0A16
Group: Malware file
Last Updated: April 27, 2017
%WINDIR%\XXXXXXAABF3161\svchsot.exe File name: svchsot.exe
Size: 632.72 KB (632720 bytes)
MD5: 8a6cf9822ba540ab2a53a969bf156525
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\XXXXXXAABF3161
Group: Malware file
Last Updated: April 27, 2017
%WINDIR%\XXXXXX7F4689D0\svchsot.exe File name: svchsot.exe
Size: 196.6 KB (196608 bytes)
MD5: 91c2d318498c32a1283cf5ce750cf20f
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\XXXXXX7F4689D0
Group: Malware file
Last Updated: April 27, 2017
%WINDIR%\XXXXXX999DE06D\svchsot.exe File name: svchsot.exe
Size: 196.6 KB (196608 bytes)
MD5: ab41d5f5b66300231dc60b95d8bccda1
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\XXXXXX999DE06D
Group: Malware file
Last Updated: April 27, 2017
%WINDIR%\XXXXXX579E5A5B VVVVVVrr2unw==\svchsot.exe File name: svchsot.exe
Size: 196.6 KB (196608 bytes)
MD5: cb5b3107a3fec86c7ac2df9069954d16
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\XXXXXX579E5A5B VVVVVVrr2unw==
Group: Malware file
Last Updated: April 27, 2017
%WINDIR%\489505AD\svchsot.exe File name: svchsot.exe
Size: 79.87 KB (79872 bytes)
MD5: 4f30e756d860060e55c9d24d3bfd130d
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\489505AD
Group: Malware file
Last Updated: April 27, 2017
%WINDIR%\XXXXXX7B32C78F\svchsot.exe File name: svchsot.exe
Size: 315 MB (315006961 bytes)
MD5: 9d028c89e3146abe86f02a96036bd764
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\XXXXXX7B32C78F
Group: Malware file
Last Updated: April 27, 2017
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Backdoor.A_variant.exe File name: Backdoor.A_variant.exe
Size: 61.46 KB (61467 bytes)
MD5: f26a2bcc152d2ba697ad4508ea00959e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: March 25, 2016
[start menu]\Programs\Startup\killmdx File name: [start menu]\Programs\Startup\killmdx
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%HOMEDRIVE%\updata.exe%PROGRAMFILES%\Internet Explorer\test.exe%WINDIR%\dsawe.EXE%WINDIR%\terms.exe.exe

Additional Information

The following directories were created:
%PROGRAMFILES%\Microsoft Ogmgka%PROGRAMFILES%\mysqldata%PROGRAMFILES(x86)%\Microsoft Ogmgka%PROGRAMFILES(x86)%\mysqldata
Loading...