Backdoor

What is “Backdoor:MSIL/Torwofun.B”?

Malware Removal

The Backdoor:MSIL/Torwofun.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/Torwofun.B virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:MSIL/Torwofun.B?


File Info:

crc32: 72046BDD
md5: b92b525045cddfce46d7e82ddacc2e65
name: B92B525045CDDFCE46D7E82DDACC2E65.mlw
sha1: 82a0a698fc086df42b4a2d65c14d5cfe253d45e9
sha256: 1e589eb233e7aeb557f7bce54607d4548c0da1932d691d4c853bd8b69d7de61b
sha512: 45234621f155d30f1eb70f3822ea972a202be2059f5bb9669696bd83430a6730f2937671a90400d267876030af928e34af3416ba3510c7dcbab31dd5a7034c62
ssdeep: 1536:HmekFUOfJxIdolYO/pxhoHLA/XlHLYdW8dbBOowUPknSjdzct6QiRjOKHnGFo6j:HH8/KLK1rYdfOojl
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: installer_webasm.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: installer_webasm.exe

Backdoor:MSIL/Torwofun.B also known as:

K7AntiVirusTrojan ( 0055e3e71 )
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop6.3845
CynetMalicious (score: 99)
ALYacGen:Variant.Razy.805702
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.31166
SangforRansom.Win32.Blocker.8
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0055e3e71 )
Cybereasonmalicious.045cdd
ESET-NOD32a variant of MSIL/Agent.QDR
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.gutk
BitDefenderGen:Variant.Razy.805702
NANO-AntivirusTrojan.Win32.Badur.dzthgt
MicroWorld-eScanGen:Variant.Razy.805702
TencentWin32.Trojan.Blocker.Pepn
Ad-AwareGen:Variant.Razy.805702
SophosML/PE-A
ComodoBackdoor.MSIL.Bladabindi.ABC@6b1idd
BitDefenderThetaGen:NN.ZemsilF.34722.km0@aubyzan
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.b92b525045cddfce
EmsisoftGen:Variant.Razy.805702 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.ibq
AviraHEUR/AGEN.1106288
Antiy-AVLTrojan/Generic.ASMalwS.13E01C2
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftBackdoor:MSIL/Torwofun.B
ArcabitTrojan.Razy.DC4B46
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Razy.805702
AhnLab-V3Trojan/Win32.Torwofun.R192172
McAfeeGenericRXAL-SO!B92B525045CD
MAXmalware (ai score=83)
PandaTrj/CI.A
YandexTrojan.Agent!ddnvX0ddWxA
IkarusTrojan.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Blocker.GUTK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor:MSIL/Torwofun.B?

Backdoor:MSIL/Torwofun.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment