Home Malware Programs Backdoors Tofsee.D

Tofsee.D

Posted: December 1, 2010

Threat Metric

Threat Level: 6/10
Infected PCs: 59
First Seen: December 1, 2010
OS(es) Affected: Windows

Aliases

BackDoor.Generic12.AVFC [AVG]Backdoor.Tofsee!IK [a-squared]Trojan/Win32.Pakes.gen [Antiy-AVL]Trojan.Dropper.Gen [McAfee-GW-Edition]Rootkit.Win32.Pakes.aat [Kaspersky]Rootkit.Pakes.aat [CAT-QuickHeal]BackDoor.Generic13.PYF [AVG]Win32.TRRootkit [eSafe]Artemis!CAD09E0ED95E [McAfee]Suspicious file [Panda]BackDoor.Generic13.AVQA [AVG]Artemis!8BC3410FE5B1 [McAfee]Artemis!C67E4093008B [McAfee]Agent2.CAEL [AVG]Win-Trojan/Tofsee.51968 [AhnLab-V3]
More aliases (102)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\System32\DRIVERS\ndisvvan.sys File name: ndisvvan.sys
Size: 45.31 KB (45312 bytes)
MD5: 40b99f27bd5311cdf4e7d418273e726e
Detection count: 91
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: December 7, 2010
%WINDIR%\System32\DRIVERS\ndisvvan.sys File name: ndisvvan.sys
Size: 51.71 KB (51712 bytes)
MD5: 1367c65a2c10c7ab94ed55429be9fce7
Detection count: 74
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: December 14, 2010
%WINDIR%\System32\DRIVERS\ndisvvan.sys File name: ndisvvan.sys
Size: 54.65 KB (54656 bytes)
MD5: 8bc3410fe5b11bb9e4cecdd57366bebd
Detection count: 66
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: April 15, 2011
%WINDIR%\System32\DRIVERS\ndisvvan.sys File name: ndisvvan.sys
Size: 46.14 KB (46144 bytes)
MD5: 8b5ca6dabcda3a731a32f3c3cb761da5
Detection count: 36
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: February 1, 2011
%WINDIR%\System32\DRIVERS\ndisvvan.sys File name: ndisvvan.sys
Size: 51.23 KB (51232 bytes)
MD5: 32b24ddd9f11f9e1c967e70aff64bc6a
Detection count: 9
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: December 1, 2010
%WINDIR%\System32\DRIVERS\ndisvvan.sys File name: ndisvvan.sys
Size: 49.4 KB (49408 bytes)
MD5: 73536cc4fc73f700d887e744d578e8e0
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: December 8, 2010
%WINDIR%\System32\DRIVERS\ndisvvan.sys File name: ndisvvan.sys
Size: 54.01 KB (54016 bytes)
MD5: cce4d5907a8fe510da76592c091f732b
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: December 1, 2010
%WINDIR%\System32\DRIVERS\ndisvvan.sys File name: ndisvvan.sys
Size: 51.96 KB (51968 bytes)
MD5: fdcff07b1cd438d72951c3f2ce904597
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: February 10, 2011
%WINDIR%\System32\DRIVERS\ndisvvan.sys File name: ndisvvan.sys
Size: 53.66 KB (53664 bytes)
MD5: c67e4093008b0e4c73d7fe84fa7c780b
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: March 14, 2011
Loading...