Backdoor

Backdoor.Win32.Tofsee information

Malware Removal

The Backdoor.Win32.Tofsee is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Tofsee virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Tofsee?


File Info:

crc32: 1314B608
md5: c40947275ff81c586bc803fcc4847a28
name: upload_file
sha1: b55ba6e1e3ef36bbcc6d17f258be586526f12b8e
sha256: 466f0beab5744a1cebd4cb3de457d3c0821d972e27e25ca1969677716c6b8c6c
sha512: a7c8212c686b3a304c2f4d00be2c48cb842f18b89a75fbd37aa5ce36a6633e9e7f7e3710dce20c435aec145549c327918aa642d2e61a9dedb612a15445ae5133
ssdeep: 3072:YMNieWx3y2vXC3oEBjgW1I/d2iZRWhtL+s6RmoDKgOkXwch4SZjjjjjjj9:3VZjgvFhRmtamHgOkXdhFv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: znakjoobz.exe
FileVers: 1.2.58
Copyright: Copyrighd (C) 2020, hupk
TranslationUsi: 0x0032 0x0ccf

Backdoor.Win32.Tofsee also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44013818
CAT-QuickHealBackdoor.Tofsee
McAfeePacked-GCZ!C40947275FF8
CylanceUnsafe
AegisLabTrojan.Win32.Tofsee.m!c
SangforMalware
K7AntiVirusTrojan-Downloader ( 0052c9d61 )
BitDefenderTrojan.GenericKD.44013818
K7GWTrojan-Downloader ( 0052c9d61 )
Cybereasonmalicious.1e3ef3
TrendMicroBackdoor.Win32.TOFSEE.USMANJ820
CyrenW32/Trojan.GQUL-0124
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
AlibabaTrojanDownloader:Win32/Zurgop.2bb838f1
NANO-AntivirusTrojan.Win32.Tofsee.hzddse
ViRobotTrojan.Win32.Z.Zurgop.225792
Ad-AwareTrojan.GenericKD.44013818
EmsisoftTrojan.GenericKD.44013818 (B)
ComodoMalware@#1twys1iri07z8
DrWebTrojan.DownLoader34.61428
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FireEyeGeneric.mg.c40947275ff81c58
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
GDataTrojan.GenericKD.44013818
JiangminBackdoor.Tofsee.cxi
MaxSecureTrojan.Malware.8956949.susgen
MAXmalware (ai score=99)
Antiy-AVLTrojan[Backdoor]/Win32.Tofsee
ArcabitTrojan.Generic.D29F98FA
ZoneAlarmHEUR:Backdoor.Win32.Tofsee.gen
MicrosoftExploit:Win32/ShellCode!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MalPe.R352683
Acronissuspicious
ALYacTrojan.SmokeLoader
VBA32Backdoor.Tofsee
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32Win32/TrojanDownloader.Zurgop.DA
TrendMicro-HouseCallBackdoor.Win32.TOFSEE.USMANJ820
RisingTrojan.Kryptik!1.CD46 (CLASSIC)
IkarusTrojan.Win32.Glupteba
eGambitUnsafe.AI_Score_88%
FortinetW32/Kryptik.HGQB!tr
WebrootW32.Trojan.Gen
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM10.2.6BC2.Malware.Gen

How to remove Backdoor.Win32.Tofsee?

Backdoor.Win32.Tofsee removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment