Worm

Worm:Win32/Tufik.A information

Malware Removal

The Worm:Win32/Tufik.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Tufik.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Worm:Win32/Tufik.A?


File Info:

name: 22A4A9D7FB78910D0FF0.mlw
path: /opt/CAPEv2/storage/binaries/261821088e912944893f851b3b0b445268f65660f4afaccd4d5f668f8d76d81b
crc32: A89BB6E2
md5: 22a4a9d7fb78910d0ff0c75d6138bfa4
sha1: 14617a7f5cdec63a0032f81f036a3b0e91f7991d
sha256: 261821088e912944893f851b3b0b445268f65660f4afaccd4d5f668f8d76d81b
sha512: 1b54f20a8e1f7e631de5037c3348c97a0b5fd7f24ff4de276ca7cee8b7b46783d4e1aa7af13ad183666860c0c572ee351d197f0c2b620558694025be9089ffd1
ssdeep: 6144:GguedLWXYds5wIaQcr2888888888888W888888888884MQ:GadLWDi2888888888888W8888888888t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E834595363424E30D27C4A72C0D294D88C277ABD09FAF0A29EB5E50E7934E85DB7794B
sha3_384: 0293945f12ff6dc1c900f3e9a4f17e165376eca4ae5fa53aea20f471e9ce27cbbc469b9dc48bfb60548cdc6d4e1d6825
ep_bytes: e8000000005b81eb193a4000ff3424e8
timestamp: 2016-04-06 14:39:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: http://www.animiz.cn
FileDescription: 万彩动画大师
FileVersion: 2.5.4
LegalCopyright: Copyright © 2018 Animiz
ProductName: 万彩动画大师
ProductVersion: 2.5.4
Translation: 0x0000 0x04b0

Worm:Win32/Tufik.A also known as:

BkavW32.Tufei503.PE
MicroWorld-eScanWin32.Tufik.A
CAT-QuickHealW32.Tufik.gen
SkyhighBehavesLike.Win32.Downloader.dm
McAfeeW32/Tufik.worm.gen
MalwarebytesGeneric.Malware.AI.DDS
ZillyaVirus.Tufik.Win32.2
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 0008d7501 )
K7GWVirus ( 0008d7501 )
Cybereasonmalicious.7fb789
BaiduWin32.Virus.Tufik.c
VirITWin32.Tufik.A
SymantecW32.Tufik
Elasticmalicious (high confidence)
ESET-NOD32Win32/Tufik.A
TrendMicro-HouseCallPE_TUFIK.B
ClamAVWin.Trojan.Tufik-3
KasperskyVirus.Win32.Tufik.a
BitDefenderWin32.Tufik.A
NANO-AntivirusVirus.Win32.Tufik.cdpn
AvastWin32:Tufik
TencentVirus.Win32.Tufik.cb
SophosW32/Tufik-A
F-SecureMalware.W32/Tufik.J
DrWebWin32.Tufei.13798
VIPREWin32.Tufik.A
TrendMicroPE_TUFIK.B
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.22a4a9d7fb78910d
EmsisoftWin32.Tufik.A (B)
IkarusVirus.Win32.Tufik
JiangminWin32/Tufei.a
GoogleDetected
AviraW32/Tufik.J
VaristW32/Heuristic-162!Eldorado
Antiy-AVLVirus/Win32.Tufik.gen
KingsoftWin32.Adata.e.141312
MicrosoftWorm:Win32/Tufik.A
XcitiumVirus.Win32.Tufik.NAA3@1isirh
ArcabitWin32.Tufik.A
ZoneAlarmVirus.Win32.Tufik.a
GDataWin32.Tufik.A
CynetMalicious (score: 100)
AhnLab-V3Win32/Tufik
VBA32Virus.Win32.Tufei.13798
ALYacWin32.Tufik.A
MAXmalware (ai score=83)
Cylanceunsafe
PandaW32/Tufei.A
RisingWorm.Tufei!1.6932 (CLASSIC)
YandexWin32.Perez.B
SentinelOneStatic AI – Suspicious PE
MaxSecureVirus.W32.Tufik.A
FortinetW32/Tufik.AS
BitDefenderThetaAI:FileInfector.CEA3F5A10D
AVGWin32:Tufik
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm:Win32/Tufik.A?

Worm:Win32/Tufik.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment