Virus

Virus:Win32/Tufik.C removal guide

Malware Removal

The Virus:Win32/Tufik.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Tufik.C virus can do?

  • Uses Windows utilities for basic functionality
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Virus:Win32/Tufik.C?


File Info:

name: AB4F4D665EF7DEB1C023.mlw
path: /opt/CAPEv2/storage/binaries/74d0caacd6b69ceec0eb8038449f683ab11ff6de08d745d7a75a36f0c95bd9d0
crc32: DD9FE3BB
md5: ab4f4d665ef7deb1c02369e1967ce48d
sha1: e0c16b60a4aff05d6ab51bfde83751427d0ba6e7
sha256: 74d0caacd6b69ceec0eb8038449f683ab11ff6de08d745d7a75a36f0c95bd9d0
sha512: fe6646f0c819b012df4a2636b70b87c1b1a9565780420d62f6f9f59acfc1295badedf675becf34683e093d876f93d7f87b3d4c31bc778e31e256103e2e7584fc
ssdeep: 3072:s/esDjpu8TOYaQ5i6+xx0ykhV4fuvXFrx7g:nsD7akT+xsV4arx7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9146D0B3B43D94AD4460E76785BC4E81AB0AF131E1A921BB251BB1FBF353C49D8317A
sha3_384: 5e0036776ee1f68e03fed1166432d562662bfa223b2fb13848bf1bee9a7fdcfbad9361afa8c3937cde619b347f2e4d1c
ep_bytes: e8000000005b81ebb91a4000ff3424e8
timestamp: 2007-04-30 11:12:01

Version Info:

Comments:
CompanyName: Thunder Networking Technologies,LTD
FileDescription:
FileVersion: 5, 6, 2, 11
InternalName: Thunder
LegalCopyright: Copyright (c) 2003-2006 Thunder Networking Technologies,LTD
LegalTrademarks:
OriginalFilename: Thunder.EXE
PrivateBuild:
ProductName: Thunder
ProductVersion: 5, 6, 2, 11
SpecialBuild:
Translation: 0x0804 0x04b0

Virus:Win32/Tufik.C also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Tufik.leKk
MicroWorld-eScanWin32.Tufik.M
FireEyeGeneric.mg.ab4f4d665ef7deb1
CAT-QuickHealW32.Tufik.gen
ALYacWin32.Tufik.M
MalwarebytesGeneric.Malware.AI.DDS
VIPREWin32.Tufik.M
K7AntiVirusVirus ( 004c1ed51 )
AlibabaVirus:Win32/Tufik.f6e4f8ab
K7GWVirus ( 004c1ed51 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITWin32.Tufik.A
CyrenW32/Virtumonde.BW.gen!Eldorado
SymantecW32.Bufei
Elasticmalicious (high confidence)
ESET-NOD32Win32/Tufik.NAA
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Sid.a
BitDefenderWin32.Tufik.M
NANO-AntivirusVirus.Win32.Sid.bnkjs
AvastWin32:Evo-gen [Trj]
TencentVirus.Win32.BlackSeeder.a
SophosW32/Tufik-Fam
F-SecureTrojan.TR/Patched.Gen2
DrWebTrojan.DownLoader.4268
ZillyaWorm.Tufik.Win32.18
TrendMicroPE_TUFIK.AA
McAfee-GW-EditionBehavesLike.Win32.Almanahe.dz
Trapminemalicious.moderate.ml.score
EmsisoftWin32.Tufik.M (B)
IkarusVirus.Win32.Tufik
GDataWin32.Tufik.M
JiangminTrojanDownloader.Agent.dgb
WebrootVirus:Win32/Tufik.C
AviraTR/Patched.Gen2
Antiy-AVLWorm/Win32.Sid.a
XcitiumWorm.Win32.Sid.a0@1c5hqm
ArcabitWin32.Tufik.M
ZoneAlarmWorm.Win32.Sid.a
MicrosoftVirus:Win32/Tufik.C
GoogleDetected
AhnLab-V3Win32/Tufik.F
McAfeeW32/Tufik.worm.c.a!inf
MAXmalware (ai score=82)
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Chgt.AC
TrendMicro-HouseCallPE_TUFIK.AA
RisingVirus.Rincux!1.9B8C (CLASSIC)
YandexTrojan.GenAsa!nUqFmzP9FJs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.W32.Packer.Upack0.3.9
FortinetW32/Tufik.AS
BitDefenderThetaAI:FileInfector.C715B98A0D
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Virus:Win32/Tufik.C?

Virus:Win32/Tufik.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment