Trojan

TrojanDownloader:Win32/Dofoil.AD (file analysis)

Malware Removal

The TrojanDownloader:Win32/Dofoil.AD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What TrojanDownloader:Win32/Dofoil.AD virus can do?

  • Unconventionial language used in binary resources: Nepali
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Dofoil.AD?


File Info:

crc32: 6450120B
md5: 86b4f42bf49d46d33bce7771990c8611
name: index.exe
sha1: bdb3d648e7dc23bfbc9abf7cdf95ed10b679b1fb
sha256: 03a36d9fc147a517b5ff3ad1f01e4bfcd61390988e671886256b2b56a8d415ec
sha512: be36065e71068f62bb4795a8ccba97b4f4595281794da331825d617fb0e31ffedcce90cd0f743eb63ca41066fae75fca8f52644a41e6f2985c35d008b21e9635
ssdeep: 3072:JTNMnDLgvmXG6wnzJcou3aBt6bwlomVUpzRSFgI:LMwvPu3k4XSFgI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Dofoil.AD also known as:

MicroWorld-eScanTrojan.GenericKD.42025687
CAT-QuickHealRansom.Stop.MP4
McAfeeRDN/Generic Downloader.x
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Tofsee.m!c
K7AntiVirusTrojan ( 0055b9c71 )
BitDefenderTrojan.GenericKD.42025687
K7GWTrojan ( 0055b9c71 )
Invinceaheuristic
F-ProtW32/Kryptik.AQX.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataTrojan.GenericKD.42025687
KasperskyBackdoor.Win32.Tofsee.calv
RisingDownloader.Dofoil!8.322 (TFE:6:qFwI1sROWJO)
Endgamemalicious (high confidence)
ComodoMalware@#24t9ob4nys7it
DrWebTrojan.DownLoader30.42259
McAfee-GW-EditionBehavesLike.Win32.IstartSurf.cm
FireEyeGeneric.mg.86b4f42bf49d46d3
SophosMal/Generic-S
IkarusTrojan.Win32.Krypt
CyrenW32/Kryptik.AQX.gen!Eldorado
JiangminBackdoor.Agent.gnb
WebrootW32.Adware.Installcore
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Tofsee
ArcabitTrojan.Generic.D28142D7
ZoneAlarmBackdoor.Win32.Tofsee.calv
MicrosoftTrojanDownloader:Win32/Dofoil.AD
AhnLab-V3Trojan/Win32.MalPe.R299695
Acronissuspicious
VBA32BScope.Trojan.Wacatac
ALYacTrojan.GenericKD.42025687
Ad-AwareTrojan.GenericKD.42025687
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GYLY
TrendMicro-HouseCallTROJ_FRS.VSNW12K19
FortinetW32/GenKryptik.DXWH!tr
BitDefenderThetaGen:NN.ZexaF.32253.mKW@ae7!7flG
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360HEUR/QVM10.2.4761.Malware.Gen

How to remove TrojanDownloader:Win32/Dofoil.AD?

TrojanDownloader:Win32/Dofoil.AD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment