Backdoor

How to remove “Backdoor.Tofsee.Gen (B)”?

Malware Removal

The Backdoor.Tofsee.Gen (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Tofsee.Gen (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
intweb.mobwork.net

How to determine Backdoor.Tofsee.Gen (B)?


File Info:

crc32: 65C3F420
md5: a01d7ce4a92c304d081a66286b1a8308
name: A01D7CE4A92C304D081A66286B1A8308.mlw
sha1: 9eeda126dfe3551fe2b4b26c296a15c81dc82d6e
sha256: dd7a4e92d4d5cb74d06a35fce97be2c27dd00432912315b422df76604cfc088a
sha512: 77e6a47067bbe469394e48b9c98dbfc6d7181c28d48dde9fcea83bdd97f531b1bb90b3c0c03d0eb434869ced1304b8dadb720251acf12cd1016b0b5adda59f8e
ssdeep: 1536:AGvD9pZA/PWblsZMSY+A37feaCMJDmYsLIb4PvYqHB/AdGD:AGL90/PgsZMSDADeak7dJHB/AdGD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 1996-2010 Adobe, Inc.
InternalName: Adobe? Flash? Player Installer/Uninstaller 10.1
FileVersion: 10,1,53,64
CompanyName: Adobe Systems, Inc.
LegalTrademarks: Adobe? Flash? Player
ProductName: Flash? Player Installer/Uninstaller
ProductVersion: 10,1,53,64
FileDescription: Adobe? Flash? Player Installer/Uninstaller 10.1 r53
OriginalFilename: FlashUtil.exe
Translation: 0x0409 0x04b0

Backdoor.Tofsee.Gen (B) also known as:

BkavW32.InjectBPS.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Tofsee.Gen
FireEyeGeneric.mg.a01d7ce4a92c304d
CAT-QuickHealTrojan.Bagsu.P4.mue
McAfeeBackDoor-EYG
CylanceUnsafe
VIPRETrojan.Win32.Inject.cj (v)
SangforMalware
K7AntiVirusTrojan ( 002331771 )
BitDefenderBackdoor.Tofsee.Gen
K7GWTrojan ( 001fbdf71 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.Inject.bf
CyrenW32/Injector.AV.gen!Eldorado
SymantecTrojan.Dropper
APEXMalicious
AvastWin32:Taidoor-D [Trj]
ClamAVWin.Trojan.Inject-132
KasperskyTrojan.Win32.Inject.bbyo
NANO-AntivirusTrojan.Win32.Inject.csnmkc
TencentTrojan.Win32.Inject.bbyoa
Ad-AwareBackdoor.Tofsee.Gen
SophosML/PE-A + Troj/CeeInj-M
ComodoTrojWare.Win32.Inject.ka@4o81ww
F-SecureMalware.W32/Almanahe.C
DrWebTrojan.DownLoad2.36100
ZillyaTrojan.InjectGen.Win32.5
TrendMicroTROJ_KRYPTK.SMS
McAfee-GW-EditionBehavesLike.Win32.Backdoor.kc
EmsisoftBackdoor.Tofsee.Gen (B)
IkarusBackdoor.Win32.Simbot
AviraW32/Almanahe.C
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Inject.bbyo
MicrosoftTrojan:Win32/Dorv.A
ArcabitBackdoor.Tofsee.Gen
SUPERAntiSpywareBackdoor.Bot/Variant
ZoneAlarmTrojan.Win32.Inject.bbyo
GDataBackdoor.Tofsee.Gen
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.CSon.R7666
Acronissuspicious
BitDefenderThetaAI:Packer.515AA8091F
ALYacBackdoor.Tofsee.Gen
VBA32SScope.Backdoor.Simbot
MalwarebytesSimbot.Backdoor.Stealer.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.ELH
TrendMicro-HouseCallTROJ_KRYPTK.SMS
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.GenAsa!5YxMY2U2QLk
SentinelOneStatic AI – Malicious PE – Spyware
MaxSecureTrojan.Inject.bbyo
FortinetW32/Injector.ELH!tr
AVGWin32:Taidoor-D [Trj]
Qihoo-360Win32/Virus.b49

How to remove Backdoor.Tofsee.Gen (B)?

Backdoor.Tofsee.Gen (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment