Backdoor

Backdoor.TofseePMF.S25754226 removal instruction

Malware Removal

The Backdoor.TofseePMF.S25754226 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.TofseePMF.S25754226 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Spanish (Colombia)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • CAPE detected the Tofsee malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor.TofseePMF.S25754226?


File Info:

name: FDABC01845A705FC8476.mlw
path: /opt/CAPEv2/storage/binaries/bc9011e5636453d682ddde2e33bcf033536a8adab7ed6c2d2e3cc5c59141d13f
crc32: 38AB5968
md5: fdabc01845a705fc847627b4a1e51cba
sha1: 6ccec3ce060d935b8af3404e5814ed2e183463f1
sha256: bc9011e5636453d682ddde2e33bcf033536a8adab7ed6c2d2e3cc5c59141d13f
sha512: 1ecda7f0545fab235c00afadf426b90c99723a6173f9dd5d8324c6c0a666392dd124afff9088c049b329d1c339e6afb07f6ed2d3b12511d27b424c83d8cfeceb
ssdeep: 12288:NbwFnsT7pnRE475asS1rWnm4////////////////////////////////////////:NbwFnsPE475S1u
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13EB67CB50B6516B9E02704BF766CBF1DCAFDA9B16369C1E79820D4D68052F3128F620F
sha3_384: 1ff9dc1676ec2d5e4eed2425dd4f7e294e21ac1cffc29de9668664b4d1fe5128c51301570ce7ca8d24c3a1c09a5bfd15
ep_bytes: 8bff558bece8b6360000e8110000005d
timestamp: 2020-11-23 14:09:22

Version Info:

0: [No Data]

Backdoor.TofseePMF.S25754226 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.fdabc01845a705fc
CAT-QuickHealBackdoor.TofseePMF.S25754226
McAfeePacked-GEE!FDABC01845A7
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3655838
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058bfeb1 )
K7GWTrojan ( 0058bfeb1 )
BaiduWin32.Trojan.Kryptik.jm
CyrenW32/Kryptik.FYI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNSW
APEXMalicious
ClamAVWin.Packed.Tofsee-9919315-1
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderTrojan.GenericKDZ.82060
NANO-AntivirusTrojan.Win32.Tofsee.jjnsev
MicroWorld-eScanTrojan.GenericKDZ.82060
AvastWin32:CrypterX-gen [Trj]
TencentBackdoor.Win32.Tofsee.16000134
Ad-AwareTrojan.GenericKDZ.82060
EmsisoftTrojan.GenericKDZ.82060 (B)
DrWebTrojan.PWS.Vidar.15
McAfee-GW-EditionPacked-GEE!FDABC01845A7
SophosML/PE-A
IkarusTrojan.Win32
GDataWin32.Trojan.BSE.1R8QSDA
JiangminBackdoor.Mokes.exm
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34F7C3E
MicrosoftTrojan:Win32/Azorult.RM!MTB
AhnLab-V3Trojan/Win.Generic.R459566
Acronissuspicious
ALYacTrojan.GenericKDZ.82060
MAXmalware (ai score=85)
VBA32BScope.Malware-Cryptor.SmokeSoviet
MalwarebytesTrojan.MalPack.GS
RisingMalware.Obscure/Heur!1.9E03 (RDMK:cmRtazpPCknBaAcJ+9WBCTEVMJ5M)
YandexTrojan.Kryptik!+9k7nUaxe9c
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_90%
FortinetW32/Kryptik.FSC!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove Backdoor.TofseePMF.S25754226?

Backdoor.TofseePMF.S25754226 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment