Trojan

About “Trojan-Downloader.Win32.Dofoil.chfu” infection

Malware Removal

The Trojan-Downloader.Win32.Dofoil.chfu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Dofoil.chfu virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity detected but not expressed in API logs

How to determine Trojan-Downloader.Win32.Dofoil.chfu?


File Info:

crc32: 291785F5
md5: 05dc0b2feae738b848045d4232f1d27c
name: tmpkf37erp0
sha1: 9fdb774bab4d344cf5b227226d48e91a56323f3c
sha256: e126daa4a53f816c178c9ed08487e59d4597d45049874768fcd32b6540b6d0d7
sha512: 9d1491d2c325a7c123502931dae749a0108dadaa52a0450be03ddac23a61040e57897374931e5bfd91852ed4a63e1d3e96e3df9659f467d448bcec559d677b30
ssdeep: 24576:AyINjLox0UG6+Dn302pqa5ugHd+Xfyze9Ln8eoSg1vpADshONKNi:AyQu0U3i302pcgHd+X6zSwvpip
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: DRx415x410x41c
Comments: This installation was built with Inno Setup.
ProductName: DRx415x410x41c
ProductVersion: 7.45
FileDescription: DRx415x410x41c Setup
Translation: 0x0000 0x04b0

Trojan-Downloader.Win32.Dofoil.chfu also known as:

Qihoo-360HEUR/QVM06.1.18D1.Malware.Gen
McAfeeArtemis!05DC0B2FEAE7
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:Malware-gen
GDataWin32.Trojan.Ilgergop.SHXBHO
KasperskyTrojan-Downloader.Win32.Dofoil.chfu
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.tc
IkarusTrojan.Dofoil
JiangminTrojan.Propagate.bwd
ZoneAlarmTrojan-Downloader.Win32.Dofoil.chfu
MicrosoftTrojan:Win32/Wacatac.D!ml
MalwarebytesTrojan.Propagate
BitDefenderThetaGen:NN.ZexaF.34128.oq0@ae3djJnG
AVGWin32:Malware-gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Downloader.Win32.Dofoil.chfu?

Trojan-Downloader.Win32.Dofoil.chfu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment