Trojan

Trojan:Win32/Totbrick.C removal

Malware Removal

The Trojan:Win32/Totbrick.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Totbrick.C virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Exhibits behavior characteristic of TrickBot banking trojan
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Attempts to create a known TrickBot mutex.

How to determine Trojan:Win32/Totbrick.C?


File Info:

crc32: 62E925AB
md5: 218613f0f1d2780f08e754be9e6f8c64
name: upload_file
sha1: fdc4c8f29642c3a9a9aa2180b3cca7d95d8c35e1
sha256: a162bb9219a09b302b90bc6f908e117e3fb2c722560336d378fd76a8f22f78f8
sha512: e9a2ff8c18aa653bfd7a61710a03d649780f25dc8c380f6cedc57d5c848a117abb632aade29d8c6fa71b5a612135deedc9a924da96b874fcb15c64e9da6e2e38
ssdeep: 6144:JLMNe5kFT/RK1WoJg4ouLl2pFUBm5iKsTFxcW3Qt07kjnnnnM:JLMMktpUWoJg4ouLsFUICcYQmkjnnnnM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Totbrick.C also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Agent.ABWI
FireEyeGeneric.mg.218613f0f1d2780f
McAfeeGenericRXAV-IC!218613F0F1D2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0055e3dd1 )
BitDefenderBackdoor.Agent.ABWI
K7GWTrojan ( 0055e3dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
InvinceaMal/Generic-R + Mal/EncPk-AGS
SymantecTrojan.Gen
APEXMalicious
AvastWin32:TrickBot-A [Drp]
ClamAVWin.Trojan.Generic-7803
KasperskyTrojan-Banker.Win32.CoreBot.bm
AlibabaTrojanBanker:Win32/CoreBot.295da50c
NANO-AntivirusTrojan.Win32.CoreBot.elkfft
ViRobotTrojan.Win32.U.Agent.202752.B
AegisLabTrojan.Win32.CoreBot.tnhI
RisingTrojan.Totbrick!8.E0F0 (TFE:5:vh8CkXCt8mC)
Ad-AwareBackdoor.Agent.ABWI
TACHYONBanker/W32.CoreBot.207360
EmsisoftBackdoor.Agent.ABWI (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader22.63827
ZillyaTrojan.CoreBot.Win32.9
TrendMicroTSPY_TRICKLOAD.Y
McAfee-GW-EditionBehavesLike.Win32.Ransomware.dc
SophosMal/EncPk-AGS
SentinelOneDFI – Malicious PE
JiangminTrojan.Banker.CoreBot.i
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Banker]/Win32.CoreBot
MicrosoftTrojan:Win32/Totbrick.C
ArcabitBackdoor.Agent.ABWI
SUPERAntiSpywareTrojan.Agent/Gen-Banker
ZoneAlarmTrojan-Banker.Win32.CoreBot.bm
GDataBackdoor.Agent.ABWI
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Trickbot.C1620377
Acronissuspicious
BitDefenderThetaAI:Packer.042D2D7A1F
ALYacBackdoor.Agent.ABWI
MAXmalware (ai score=100)
VBA32TrojanBanker.CoreBot
MalwarebytesSpyware.TrickBot
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrickBot.A
TrendMicro-HouseCallTSPY_TRICKLOAD.Y
TencentMalware.Win32.Gencirc.10b76bbc
YandexTrojan.GenAsa!qlD6f8hjMq8
IkarusTrojan-Banker.TrickBot
eGambitUnsafe.AI_Score_93%
FortinetW32/Generic.AC.3965A8!tr
WebrootTrojan.Banker.Corebot
AVGWin32:TrickBot-A [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.BO.7dd

How to remove Trojan:Win32/Totbrick.C?

Trojan:Win32/Totbrick.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment