Trojan

How to remove “Trojan:Win32/Tofsee.RW!MTB”?

Malware Removal

The Trojan:Win32/Tofsee.RW!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Tofsee.RW!MTB virus can do?

  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Tofsee.RW!MTB?


File Info:

name: 21CF59054DDDB4C2C777.mlw
path: /opt/CAPEv2/storage/binaries/c6d8d3c66e6a0fcce4e55c6bf581624b5ece76c3abd96ff9a40ab0402834beb3
crc32: 7919B5D7
md5: 21cf59054dddb4c2c777cd71d356a660
sha1: 1ada0a1b312e07f61e9823a72ce882d0a3f4d139
sha256: c6d8d3c66e6a0fcce4e55c6bf581624b5ece76c3abd96ff9a40ab0402834beb3
sha512: 6d7d596d84accf010a624cfc5b89a6776d339da557388f44532869c8d8860fe1c10956841346907cdd07bc6f393ef828c6c4390799dee76dccf94189ee101f73
ssdeep: 3072:oZEO4EmZ3zFAIsYK47fc4rfXOjUWHwAxE:o+5EsFADn4fDAQAy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FA3F106EDDEE0A2DE85017010BAA3AADD779487977565FF6B205E265C033E0FC3925C
sha3_384: 9ffdc1d20acafb0d6aaa96d448541d2bbd947d30e0d9cf59715f777688ea016e386b6b88f3f17933b851b75c90de940b
ep_bytes: e801030000e99efdffff558bec81ec28
timestamp: 2012-11-12 03:03:28

Version Info:

0: [No Data]

Trojan:Win32/Tofsee.RW!MTB also known as:

LionicTrojan.Win32.Agent.mxel
CynetMalicious (score: 100)
FireEyeGeneric.mg.21cf59054dddb4c2
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeObfuscated-FUK!hb
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0004894b1 )
AlibabaTrojanDownloader:Win32/Gippers.0cb8fe1f
K7GWTrojan ( 0004894b1 )
Cybereasonmalicious.54dddb
BaiduWin32.Worm.Agent.ar
CyrenW32/A-b2473c7f!Eldorado
SymantecTrojan.Zbot
Elasticmalicious (high confidence)
ESET-NOD32Win32/Agent.NNV
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1116071
KasperskyTrojan-Dropper.Win32.Injector.pavc
BitDefenderGen:Variant.Zusy.342870
NANO-AntivirusTrojan.Win32.Agent.cqhzzw
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
MicroWorld-eScanGen:Variant.Zusy.342870
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b0cea0
Ad-AwareGen:Variant.Zusy.342870
EmsisoftGen:Variant.Zusy.342870 (B)
ComodoTrojWare.Win32.Agent.NVA@535btd
DrWebTrojan.StartPage.55764
ZillyaTrojan.Agent.Win32.429517
TrendMicroBKDR_TOFSEE.SMJ0
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosMal/Generic-R + Troj/Sulunch-D
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.342870
JiangminTrojan/Agent.hxgy
AviraTR/Rogue.zxdv
ArcabitTrojan.Zusy.D53B56
ViRobotTrojan.Win32.Agent.135138
MicrosoftTrojan:Win32/Tofsee.RW!MTB
TACHYONTrojan/W32.Agent.104084.B
AhnLab-V3Trojan/Win32.Agent.R85553
Acronissuspicious
VBA32Trojan.Agent
ALYacGen:Variant.Zusy.342870
MAXmalware (ai score=100)
MalwarebytesTrojan.Agent.FR
TrendMicro-HouseCallBKDR_TOFSEE.SMJ0
RisingWorm.Autorun!1.A242 (RDMK:cmRtazod4LCZz1JP+m2u3HQClo48)
YandexTrojan.GenAsa!l2AqExaJZG0
IkarusTrojan.Win32.Agent
FortinetW32/Blocker.KGW!tr
BitDefenderThetaGen:NN.ZexaF.34638.gqZ@aGtJBxfj
AVGWin32:Malware-gen
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Tofsee.RW!MTB?

Trojan:Win32/Tofsee.RW!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment