Backdoor

Backdoor.Tofsee.Gen removal

Malware Removal

The Backdoor.Tofsee.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Tofsee.Gen virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Backdoor.Tofsee.Gen?


File Info:

crc32: A149E248
md5: aee194e6f1dea94cf329429d0da6c500
name: AEE194E6F1DEA94CF329429D0DA6C500.mlw
sha1: 5d37a95892933a4d59f1ba1a3828ad0ed4b82d9f
sha256: dcdbcb83ec6a1bcc20b8ae0e8a8070493dd2d4a13b7a195c332f8abd09ef298e
sha512: 7d46f48293052aec4baf66a4ecbbd184e3ddbf7a7844464aa549fc85ec249218cd683d2074fb64a7b8bbaae9f455018cae470e8ddf38b8b61b6863a44c548ea2
ssdeep: 768:nSGV91BYl68Zdxj4q7dBCcHDQI3psZNCSSDaXdF+lF7P:nSk6lDZdxj4YB98AsZMSY+A37P
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 1996-2010 Adobe, Inc.
InternalName: Adobe? Flash? Player Installer/Uninstaller 10.1
FileVersion: 10,1,53,64
CompanyName: Adobe Systems, Inc.
LegalTrademarks: Adobe? Flash? Player
ProductName: Flash? Player Installer/Uninstaller
ProductVersion: 10,1,53,64
FileDescription: Adobe? Flash? Player Installer/Uninstaller 10.1 r53
OriginalFilename: FlashUtil.exe
Translation: 0x0409 0x04b0

Backdoor.Tofsee.Gen also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Tofsee.Gen
FireEyeGeneric.mg.aee194e6f1dea94c
CAT-QuickHealTrojan.Bagsu.P4.mue
ALYacBackdoor.Tofsee.Gen
CylanceUnsafe
VIPRETrojan.Win32.Inject.cj (v)
K7AntiVirusTrojan ( 002331771 )
BitDefenderBackdoor.Tofsee.Gen
K7GWTrojan ( 001fbdf71 )
Cybereasonmalicious.6f1dea
BitDefenderThetaAI:Packer.51A566D71F
CyrenW32/Injector.AV.gen!Eldorado
SymantecTrojan.Dropper
ESET-NOD32a variant of Win32/Injector.ELH
BaiduWin32.Trojan.Inject.bf
APEXMalicious
AvastWin32:Taidoor-D [Trj]
ClamAVWin.Trojan.Inject-132
KasperskyTrojan.Win32.Inject.bbyo
NANO-AntivirusTrojan.Win32.Inject.csnmkc
TencentTrojan.Win32.Inject.bbyoa
Ad-AwareBackdoor.Tofsee.Gen
TACHYONTrojan/W32.Inject.40960.XX
EmsisoftBackdoor.Tofsee.Gen (B)
ComodoTrojWare.Win32.Inject.ka@4o81ww
DrWebTrojan.DownLoad2.36100
ZillyaTrojan.InjectGen.Win32.5
TrendMicroTROJ_KRYPTK.SMS
McAfee-GW-EditionBehavesLike.Win32.Backdoor.pc
SophosML/PE-A + Troj/CeeInj-M
SentinelOneStatic AI – Malicious PE – Spyware
GDataBackdoor.Tofsee.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Inject.bbyo
ArcabitBackdoor.Tofsee.Gen
AhnLab-V3Backdoor/Win32.CSon.R7666
ZoneAlarmTrojan.Win32.Inject.bbyo
MicrosoftTrojan:Win32/Dorv.A
CynetMalicious (score: 100)
Acronissuspicious
McAfeeBackDoor-EYG
MAXmalware (ai score=81)
VBA32SScope.Backdoor.Simbot
MalwarebytesSimbot.Backdoor.Stealer.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SMS
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
YandexTrojan.GenAsa!5YxMY2U2QLk
IkarusBackdoor.Win32.Simbot
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ELH!tr
AVGWin32:Taidoor-D [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.2fa

How to remove Backdoor.Tofsee.Gen?

Backdoor.Tofsee.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment