Trojan

About “Trojan:Win32/Tofumanics.D” infection

Malware Removal

The Trojan:Win32/Tofumanics.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Tofumanics.D virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk

How to determine Trojan:Win32/Tofumanics.D?


File Info:

name: 0D173CA30F2986BCBED5.mlw
path: /opt/CAPEv2/storage/binaries/855f112064f9a3def592c58ca1a4983e1d697f85475ebf34631bee49039d8b26
crc32: A7EE5B75
md5: 0d173ca30f2986bcbed552d6a0041f3c
sha1: 67cba4dfaf3ab1f3625917e0706022277dd302ef
sha256: 855f112064f9a3def592c58ca1a4983e1d697f85475ebf34631bee49039d8b26
sha512: 497ff3e1b59c65f76d1ba7635958307a9253935507ffce3197fb3ae6efbf408e2477de8f84cc235f57e163008417e6cb10b875810a060e6360a7b17aff2c0435
ssdeep: 3072:GQmD/cQvGHWPGPGttvhyn16HT7hEA4t0ML7+/iVm:xi/JGcyoztEAk0I71
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19EB3025F95094A5FE2B2D1357E0ACEBCA707F510EA210B17766EA38AAF307326D4111F
sha3_384: 4ba52797e37fd62e3745849496895994e206aac67b4386782ba79cc53aab92d5d7341fe87b4b133dffdf021c45de7428
ep_bytes: 60be00c040008dbe0050ffffc78708c0
timestamp: 2005-09-16 06:47:40

Version Info:

CompanyName: Alien
FileDescription: Mayo Felon Chris
FileVersion: 1.2
InternalName: Elk Foal Noun Rascal Verna Vets
LegalCopyright: Copyright © Guise Plea 2000-2006
OriginalFilename: Snob.exe
ProductName: Debt Boost Era Omens Runt
ProductVersion: 1.2
Translation: 0x0409 0x04b0

Trojan:Win32/Tofumanics.D also known as:

LionicTrojan.Win32.Qhost.4!c
MicroWorld-eScanTrojan.Fakealert.43618
FireEyeGeneric.mg.0d173ca30f2986bc
McAfeeArtemis!0D173CA30F29
CylanceUnsafe
ZillyaTrojan.Qhost.Win32.7430
SangforTrojan.Win32.Fakealert.43618
K7AntiVirusTrojan ( f1000f011 )
AlibabaTrojan:Win32/Kryptik.05baa44f
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.30f298
BitDefenderThetaGen:NN.ZexaF.34114.gmKfayucXQli
CyrenW32/Zbot.CN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.TJQ
TrendMicro-HouseCallTROJ_GEN.R002C0DJO21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Fakealert.43618
NANO-AntivirusTrojan.Win32.Crypted.cylvgh
AvastWin32:Rootkit-gen [Rtk]
TencentWin32.Trojan.Qhost.Fid
Ad-AwareTrojan.Fakealert.43618
SophosMal/EncPk-AAY
ComodoMalware@#4k3lq30nu058
DrWebTrojan.Hosts.4561
VIPRETrojan.Win32.EncPk.acl (v)
McAfee-GW-EditionGeneric PWS.ug
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.Fakealert.43618 (B)
APEXMalicious
GDataTrojan.Fakealert.43618
JiangminTrojan.Generic.xbhs
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Troj.Qhost.(kcloud)
MicrosoftTrojan:Win32/Tofumanics.D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Yakes.R12108
ALYacTrojan.Fakealert.43618
MAXmalware (ai score=100)
VBA32BScope.Trojan.Hoster.2791
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.Kryptik!aA4Er1U/cVo
IkarusTrojan.Win32.Ransom
eGambitGeneric.Malware
FortinetW32/Yakes.D!tr
WebrootW32.Malware.Gen
AVGWin32:Rootkit-gen [Rtk]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Tofumanics.D?

Trojan:Win32/Tofumanics.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment