Trojan

Trojan:Win32/Totbrick.A removal tips

Malware Removal

The Trojan:Win32/Totbrick.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Totbrick.A virus can do?

  • Drops a binary and executes it
  • Performs some HTTP requests
  • Looks up the external IP address
  • Deletes its original binary from disk
  • Exhibits behavior characteristic of TrickBot banking trojan
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to create a known TrickBot mutex.

Related domains:

z.whorecord.xyz
a.tomx.xyz
myexternalip.com

How to determine Trojan:Win32/Totbrick.A?


File Info:

crc32: 1169E503
md5: ad47d552a33d8bc35959d4004e3563e2
name: upload_file
sha1: 828f887d673a14d4e74b138dfbe56546bba7f9c0
sha256: fefa16a79d8a6a347c927629589634cde22e6869e3e5d67106902a88adbe43d2
sha512: bab8542b11f7fda9f2ec2e58f9f3d5fe0000ecc4b1fdea6a354a12ae1dcc4997d912bca2e3963eb3eb061142b5732da217c0123d1d9414b89d93729cdab36626
ssdeep: 1536:1AjfKftvj4qrL8Tv/Vx3h14cLLsKDOk9FXNBllzIRASmRT:OjYFj/rL8Tv/Vx3h14cUKDOqNBvIRANF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Totbrick.A also known as:

BkavW32.eHeur.Malware03
MicroWorld-eScanGeneric.Trojan.TrickBot.A59A3723
CAT-QuickHealTrojan.Totbrick
McAfeeGenericRXAM-PQ!AD47D552A33D
MalwarebytesSpyware.TrickBot
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 001b27e51 )
K7GWTrojan ( 001b27e51 )
Invinceapws.win32.zbal.b
SymantecTrojan Horse
TrendMicro-HouseCallTROJ_GEN.R047C0CK716
AvastWin32:TrickBot-B [Trj]
KasperskyHEUR:Trojan.Win32.Trickster.gen
BitDefenderGeneric.Trojan.TrickBot.A59A3723
NANO-AntivirusTrojan.Win32.ATRAPS.eihejf
ViRobotTrojan.Win32.Z.Trickbot.77314[h]
SUPERAntiSpywareTrojan.Agent/Gen-TDSS[Pragma]
RisingMalware.Generic!b1FDcG4JMeT@5 (thunder)
Ad-AwareGeneric.Trojan.TrickBot.A59A3723
SophosMal/Generic-S
ComodoTrojWare.Win32.TrickBot.A
F-SecureGeneric.Trojan.TrickBot.A59A3723
DrWebTrojan.DownLoader23.5515
ZillyaTrojan.Agent.Win32.725904
TrendMicroTROJ_GEN.R047C0CK716
McAfee-GW-EditionBehavesLike.Win32.Injector.lh
EmsisoftGeneric.Trojan.TrickBot.A59A3723 (B)
CyrenW32/Trojan.NOMH-0445
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[:HEUR]/Win32.Trickster
ArcabitGeneric.Trojan.TrickBot.A59A3723
AegisLabTroj.W32.Trickster!c
MicrosoftTrojan:Win32/Totbrick.A
AhnLab-V3Trojan/Win32.Trickbot.N2151120746
AVwareTrojan.Win32.Generic!BT
ESET-NOD32a variant of Win32/Agent.RYE
TencentWin32.Trojan.Trickster.Lnxv
YandexTrojan.Trickster!
IkarusTrojan.Win32.Agent
GDataGeneric.Trojan.TrickBot.A59A3723
AVGAgent5.AUPM
PandaTrj/GdSda.A
CrowdStrikemalicious_confidence_99% (W)
Qihoo-360Win32/Trojan.393

How to remove Trojan:Win32/Totbrick.A?

Trojan:Win32/Totbrick.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment