Trojan

Trojan:Win32/Tofsee.RLK!MTB removal

Malware Removal

The Trojan:Win32/Tofsee.RLK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Tofsee.RLK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Slovak
  • Detects Sandboxie through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/Tofsee.RLK!MTB?


File Info:

crc32: 7F825435
md5: 1f04ac10cd226663d26bb2fd6608ef48
name: 81678957070817713155500395278670818.exe
sha1: d3b0195f71298b534caa93d0d31e9bdc963321a4
sha256: a730d526dbd217b641b45ea134161eb8dca5f184c261f69b76c76a52c57cab9c
sha512: cca9140f7b74c16400ca0b82a251a976d6c6edf91d11c4eb05c8aa0e320f0ccc0f89ee8f0c16b0a37cb3b8d8696aabd24ba36f0969f9b979ee197db70330d26e
ssdeep: 3072:gddNFulIWIcSGuzIaeZ4TAf0I6p6q+Y+zUzdnwE9C4zfEgkmktl6tAgF/SWsyeN:gd9usvd8RfBM6qsmdnwEM4Av6F/0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Tofsee.RLK!MTB also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33769898
FireEyeGeneric.mg.1f04ac10cd226663
McAfeeRDN/Generic.grp
MalwarebytesTrojan.Glupteba
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00565ec01 )
BitDefenderTrojan.GenericKD.33769898
K7GWTrojan ( 00565ec01 )
Cybereasonmalicious.f71298
Invinceaheuristic
F-ProtW32/Kryptik.BML.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.33769898
KasperskyBackdoor.Win32.Agent.mytvqz
AlibabaBackdoor:Win32/Tofsee.0c0b71bf
SUPERAntiSpywareRansom.GandCrab/Variant
TencentWin32.Backdoor.Agent.Dyqm
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoMalware@#1bth6kjg8ct2b
DrWebTrojan.Siggen9.43893
TrendMicroTROJ_GEN.R049C0DE320
McAfee-GW-EditionRDN/Generic.grp
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.33769898 (B)
IkarusTrojan-Dropper.Win32.Danabot
CyrenW32/Trojan.CYVO-2626
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Tofsee.RLK!MTB
ArcabitTrojan.Generic.D20349AA
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmBackdoor.Win32.Agent.mytvqz
AhnLab-V3Trojan/Win32.Tofsee.R335230
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34108.rqW@aSqCTliG
MAXmalware (ai score=87)
VBA32Trojan.Wacatac
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HDBD
TrendMicro-HouseCallTROJ_GEN.R049C0DE320
RisingBackdoor.Agent!8.C5D (CLOUD)
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.100777833.susgen
FortinetW32/Kryptik.HDBD!tr
Ad-AwareTrojan.GenericKD.33769898
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Backdoor.67e

How to remove Trojan:Win32/Tofsee.RLK!MTB?

Trojan:Win32/Tofsee.RLK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment