Malware

Should I remove “Tofsee.1”?

Malware Removal

The Tofsee.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Tofsee.1 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

How to determine Tofsee.1?


File Info:

crc32: 8D57EA13
md5: a671aec33c6beb76b40ab231a363ce19
name: A671AEC33C6BEB76B40AB231A363CE19.mlw
sha1: 65d702905e76dea80f3fc09829d91113bb998beb
sha256: dddce3e85f96e21024eb4501e8096b4258bb7ea6aaf945d5955da3f6ef071c4d
sha512: b33f6896a32275984c3ac473f1717d76548f6f2b7228f6dd3aafc95f1a3a0020c4282bca36b3bd9037ddbec2cec260dc2efd76cfd587b2c1fc48352bef3f7ba7
ssdeep: 6144:YUlLTfn+LMFf4KGf5YYSuiV1n+NAOTquaSpkA0mtNjZWgriGs:1lLD+MFbGB/Suiz+NVFpCgrQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Tofsee.1 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3991 )
Elasticmalicious (high confidence)
DrWebTrojan.SpyBot.324
CynetMalicious (score: 100)
ALYacGen:Variant.Tofsee.1
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Zegost.a5d77b04
K7GWTrojan ( 0056fe231 )
Cybereasonmalicious.33c6be
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CRL
APEXMalicious
AvastWin32:Buzus-AMT [Trj]
ClamAVWin.Trojan.Buzus-8120
KasperskyBackdoor.Win32.Zegost.sfo
BitDefenderGen:Variant.Tofsee.1
NANO-AntivirusTrojan.Win32.Buzus.dfimyb
ViRobotTrojan.Win32.Buzus.354304.B
MicroWorld-eScanGen:Variant.Tofsee.1
TencentMalware.Win32.Gencirc.10b41fbb
Ad-AwareGen:Variant.Tofsee.1
SophosML/PE-A + Troj/Buzus-FQ
ComodoTrojWare.Win32.GameThief.Magania.~NWABJ@1775g1
BitDefenderThetaAI:Packer.985F77A11E
TrendMicroTROJ_WEVARM.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.a671aec33c6beb76
SentinelOneStatic AI – Malicious PE
JiangminPacked.Katusha.qzg
AviraTR/Agent.gzeh
MicrosoftVirTool:Win32/CeeInject.gen!DR
GDataGen:Variant.Tofsee.1
AhnLab-V3Trojan/Win32.Buzus.R16094
Acronissuspicious
McAfeeBackDoor-FBGC!A671AEC33C6B
MAXmalware (ai score=85)
VBA32BScope.Trojan.SvcHorse.01643
MalwarebytesMalware.AI.1195949502
PandaGeneric Malware
TrendMicro-HouseCallTROJ_WEVARM.SM
RisingTrojan.Generic@ML.100 (RDML:VMsVjiZIZKM9LBcTkY8m2w)
YandexTrojan.GenAsa!JGZwImrrb/U
IkarusVirus.Win32.Buzus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Buzus.FQ!tr
AVGWin32:Buzus-AMT [Trj]
Paloaltogeneric.ml

How to remove Tofsee.1?

Tofsee.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment