Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 842
First Seen: June 25, 2013
Last Seen: August 28, 2022
OS(es) Affected: Windows

Backdoor:Win32/Farfli.AV is a backdoor Trojan that enables a remote cybercriminal to obtain access and control to the corrupted PC. Backdoor:Win32/Farfli.AV can log keystrokes and steal an affected PC user's personal information. Backdoor:Win32/Farfli.AV can drop other malware infections on the infected computer system. Backdoor:Win32/Farfli.AV may steal the target PC user's personal information by recording his/her usernames and passwords. While being installed, Backdoor:Win32/Farfli.AV makes system modifications by adding malevolent files. Backdoor:Win32/Farfli.AV adds itself to the start menu to ensure it is executed automatically every time you start Windows. Backdoor:Win32/Farfli.AV creates a copy of itself as a malevolent file. Backdoor:Win32/Farfli.AV strives to connect to a distant server to receive commands. Backdoor:Win32/Farfli.AV alters system settings and runs or blocks programs.

File System Details

Backdoor:Win32/Farfli.AV may create the following file(s):
# File Name MD5 Detections
1. updata.exe 281e5275e39b6aa7997bd017f9ba8794 125
2. svchsot.exe 5a2417a1c607464051ec9e2c0bcad34e 62
3. svchsot.exe 377e64bc752914e0c1cb5a223d0111f0 43
4. svchsot.exe bb2b345cf7534b94b8357273870be8c6 33
5. svchsot.exe c5d017bb110b1ea9f91d77cb8eae9376 31
6. svchsot.exe e79a87fba2dd859b02d9294495b92f13 31
7. svchsot.exe 9b12bf99b9dffdb3dbaead78fee77f30 27
8. svchsot.exe 25c9e88240fde5cdb12ded7823e143ec 22
9. svchsot.exe dfcb9a0fe689528644d8ec2fc79e0d8b 22
10. svchsot.exe 571986a42b3a764108ef3ae8b2cb6405 19
11. svchsot.exe 8a6cf9822ba540ab2a53a969bf156525 14
12. svchsot.exe 91c2d318498c32a1283cf5ce750cf20f 14
13. svchsot.exe ab41d5f5b66300231dc60b95d8bccda1 14
14. svchsot.exe cb5b3107a3fec86c7ac2df9069954d16 12
15. svchsot.exe 4f30e756d860060e55c9d24d3bfd130d 10
16. svchsot.exe 9d028c89e3146abe86f02a96036bd764 10
17. svchsot.exe 3138a12a00e63bbdb716ae5edbeeb329 10
18. Backdoor.A_variant.exe f26a2bcc152d2ba697ad4508ea00959e 2
19. file.exe db10c94b48e4838b800d7a386b9836fc 1
20. [start menu]\Programs\Startup\killmdx
21. file.exe bffe4a9dff2bb714fdb748b1ad8ed146 0
22. file.exe 3319ed9745bb92fe8e58e268165d13d7 0
23. file.exe 109dd29814db94db205eddccc1e17c58 0

Registry Details

Backdoor:Win32/Farfli.AV may create the following registry entry or registry entries:
Regexp file mask
%PROGRAMFILES%\Internet Explorer\test.exe


Backdoor:Win32/Farfli.AV may create the following directory or directories:

%PROGRAMFILES%\Microsoft Ogmgka
%PROGRAMFILES(x86)%\Microsoft Ogmgka


