Threat Database Trojans Trojan.Farfli.BW

Trojan.Farfli.BW

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 142
First Seen: September 16, 2024
Last Seen: March 19, 2026
OS(es) Affected: Windows

The detection of Trojan.Farfli.BW on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating methods, symptoms of infection, and steps to remove it from your system. It is essential to take the necessary precautions to protect your personal data and prevent further damage.

What Is Trojan.Farfli.BW?

Trojan.Farfli.BW is a type of Trojan threat, which is a broad category of malware that can perform a variety of malicious functions. Trojans are often disguised as legitimate software or attachments, making them difficult to detect. They can be used to steal sensitive information, install additional malware, or provide unauthorized access to your system.

How Trojan.Farfli.BW Operates

Trojan.Farfli.BW, like other Trojans, can operate in various ways, depending on its intended purpose. It may be designed to remain stealthy, avoiding detection by security software, or it may be more overt, causing noticeable system disruptions. Trojans can spread through exploited vulnerabilities, phishing attacks, or by being bundled with other software. Once inside a system, they can communicate with their command and control servers to receive instructions or transmit stolen data.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely, making them sometimes difficult to identify. Common signs include unexpected changes to your system settings, unfamiliar programs or icons, slow system performance, frequent crashes, or pop-ups and other unwanted advertisements. Additionally, you might notice that your browser homepage has changed, or you are being redirected to suspicious websites. It's crucial to monitor your system's behavior and take action if you notice any unusual activity.

How to Remove Trojan.Farfli.BW

  1. Boot your computer in Safe Mode with Networking. This will help prevent the malware from loading and make it easier to remove.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure the tool is updated with the latest definitions to increase the chances of detecting and removing the Trojan.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the Trojan was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that the Trojan.Farfli.BW has been completely removed.

Conclusion

Removing Trojan.Farfli.BW requires careful and systematic steps to ensure that all components of the malware are eliminated from your system. It's also crucial to adopt preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong, unique passwords, and being cautious with emails and downloads from unknown sources. By understanding how Trojans operate and taking proactive steps, you can significantly reduce the risk of infection and protect your digital security.

Analysis Report

General information

Family Name: Trojan.Farfli.BW
Signature status: No Signature

Known Samples

MD5: ab622a835b8c25dac896657c308565b2
SHA1: 23b6bf6d2366f5272e0f3299cbd55be8982520a7
SHA256: BBD1333F999975A5AF427AA3D1FE48B2A6FEDABD2CA9730CBE46A92C2B4D5A5C
File Size: 6.65 MB, 6653024 bytes
MD5: 2d03ab1ac3f5a8ddaca74903f11dbd29
SHA1: 79f35f02b79dee9524faff504aa32cc5e426d199
SHA256: 6026B0BE38ABC6B50036BE1C717D231A5CE71C433C409A0BD6E1A697C8FC00D2
File Size: 6.47 MB, 6470134 bytes
MD5: 14fe84f431a3d0563b35f9d2a4411852
SHA1: 4b9bf5b91ba7eb3e3ed94cf9f4e134c9da2f5ea1
SHA256: 0F599CFEF47D6941EF472199D30538D79024D038D3FB8FA5FB8435EDB5EF5162
File Size: 6.49 MB, 6485301 bytes
MD5: 4588e89a6c095266327726dd737e9eb7
SHA1: a2c9b9366a65c8248ed2a6bf877375408591cd5a
SHA256: 307DB445C26B43B841EDEB2745317D8AA14FF8C5A8267A5646AF91DBBA67FC46
File Size: 6.69 MB, 6692133 bytes
MD5: 45e67b9d14704242e6025b38de9f86c4
SHA1: 6495b5ea194f56aca6e93311d08732ce329744dc
SHA256: EB331712E2631D83A2A2B793C7B413843646FFA17D42D0E98A8BB6EADEE634EE
File Size: 6.71 MB, 6709556 bytes
Show More
MD5: 7c25281cd0a9bcd1609735df5a6eb250
SHA1: d7f3f8fea8a16e5f15831455c66b5cc8d240282d
SHA256: 7275E557D8547AAA7A25327E6F1E1EEB58DCC6E0D8214AA564E5901534E228A3
File Size: 180.74 KB, 180736 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • dll
  • fptable
  • x86

Block Information

Total Blocks: 858
Potentially Malicious Blocks: 3
Whitelisted Blocks: 841
Unknown Blocks: 14

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? x ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 2 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 3 1 1 1 0 0 0 0 0 0 0 1 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 2 0 0 0 2 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 2 2 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 1 0 0 0 0 0 2 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 1 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.XDT
  • DefendNot.A
  • Kryptik.AFA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsb61c9.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsb61c9.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nstc523.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nstc523.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsu2af4.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsu2af4.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsw579a.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsw579a.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsxc2d1.tmp\langdll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsxc2d1.tmp\system.dll Generic Write,Read Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\d7f3f8fea8a16e5f15831455c66b5cc8d240282d_0000180736.,LiQMAxHB

Trending

Most Viewed

Loading...