Backdoor

Should I remove “Backdoor:Win32/Tofsee.BS!MTB”?

Malware Removal

The Backdoor:Win32/Tofsee.BS!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Tofsee.BS!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Tofsee.BS!MTB?


File Info:

crc32: 8256ADEA
md5: 9b410fc32632aa213a58f3467bb22dbc
name: motorolam500mp3playerfirmware-rtmd-ajvatv4obgaajrscaenofwasadg_6yya.exe
sha1: e5904b4270a56b5fc675d112f7c24de7fab025c3
sha256: d1f5263b5d8e3238639b93e6810b45095ed019e7dd20c53ade8b162f86ed0a35
sha512: e6744efd25cbd4d814cbd3d643291e97de64c0c810fe0abe34744d0ec52118716a0b7ede548b7ec8b06a1a2b7f339e063d78cd3f09b0412ef7e0830c25b7a253
ssdeep: 98304:hZUanPihpbcxdLRcXVvQVySsXo6UHPQ0QG0Q:hK9mxdLRcXXoXNQGJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersionNew: 2.3.4
InternalServiceName: speedy.exe
Copyright: Copyright (C) 2020, softtail

Backdoor:Win32/Tofsee.BS!MTB also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33325839
FireEyeGeneric.mg.9b410fc32632aa21
McAfeeArtemis!9B410FC32632
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
BitDefenderTrojan.GenericKD.33325839
Cybereasonmalicious.32632a
SymantecRansom.Nemty
APEXMalicious
GDataWin32.Trojan.Agent.KQXQKX
KasperskyTrojan.Win32.AntiAV.cvue
RisingTrojan.Kryptik!8.8 (C64:YzY0OsQt60lU6+EA)
Endgamemalicious (high confidence)
SophosMal/Generic-S
DrWebTrojan.Siggen9.13650
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.wc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.33325839 (B)
IkarusTrojan.Win32.Krypt
CyrenW32/Kryptik.BDL.gen!Eldorado
WebrootW32.Trojan.Gen
MicrosoftBackdoor:Win32/Tofsee.BS!MTB
ArcabitTrojan.Generic.D1FC830F
ZoneAlarmTrojan.Win32.AntiAV.cvue
AhnLab-V3Trojan/Win32.MalPe.R326644
BitDefenderThetaGen:NN.ZexaF.34090.UBW@aeIZLAeG
ALYacTrojan.Agent.EMCW
MAXmalware (ai score=81)
VBA32BScope.Trojan.AET.281105
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HBHP
TencentWin32.Trojan.Antiav.Hufh
SentinelOneDFI – Malicious PE
FortinetPossibleThreat.MU
Ad-AwareTrojan.GenericKD.33325839
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Backdoor:Win32/Tofsee.BS!MTB?

Backdoor:Win32/Tofsee.BS!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment