Backdoor

How to remove “Backdoor.Win32.Tofsee.clnj”?

Malware Removal

The Backdoor.Win32.Tofsee.clnj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Tofsee.clnj virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Sindhi
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Tofsee.clnj?


File Info:

crc32: 58903097
md5: 8390d9fbd194aeafb466744d6faf6940
name: him.exe
sha1: ab65d14ed4590b67ef2a562eb1c8813865431875
sha256: ce47a5851540ea877ae374e5592e711ca865d5bdb243250f9065d9c85a6ecee4
sha512: 0c75fa2ebb43771897934ded4c6680e99887b3dc737954233a59c7c4f517eaedd85ca99a5b495364805fb41ab3a3732cc753c95466d6b43dde591f7b6233c466
ssdeep: 3072:kSBzPenaRQ3iLHoI+vvEYFlKVBvHSMSXcS9ZTHhM89UbHIH+mGqYd:kSBzPenaCkoTDjKXfGnZTG8qbA+B
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Tofsee.clnj also known as:

MicroWorld-eScanTrojan.GenericKD.33272429
McAfeeArtemis!8390D9FBD194
SangforMalware
BitDefenderTrojan.GenericKD.33272429
Cybereasonmalicious.ed4590
ArcabitTrojan.Generic.D1FBB26D
Invinceaheuristic
ESET-NOD32a variant of Win32/Kryptik.HBBY
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Tofsee.clnj
NANO-AntivirusTrojan.Win32.Stealer.hanwme
Ad-AwareTrojan.GenericKD.33272429
EmsisoftTrojan.Agent (A)
DrWebTrojan.PWS.Stealer.24943
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FortinetW32/Kryptik.HBBY!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8390d9fbd194aeaf
SentinelOneDFI – Malicious PE
MAXmalware (ai score=86)
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Wacatac.D!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
AhnLab-V3Trojan/Win32.MalPe.R325901
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34090.mSW@aeQRNehG
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqNSPBATDLTtW9TH5PWMA+E)
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_99%
GDataWin32.Trojan-Stealer.Azorult.TLTIWU
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Backdoor.dfc

How to remove Backdoor.Win32.Tofsee.clnj?

Backdoor.Win32.Tofsee.clnj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment