Home Malware Programs Trojans Trojan:Win32/Tobfy.I

Trojan:Win32/Tobfy.I

Posted: November 21, 2012

Threat Metric

Ranking: 14,504
Threat Level: 9/10
Infected PCs: 267
First Seen: November 21, 2012
Last Seen: March 9, 2025
OS(es) Affected: Windows

Trojan:Win32/Tobfy.I a ransomware Trojan that is used by scammers to distribute ransomware programs such as Interpol Department of Cybercrime Ransomware and FBI Moneypak Ransomware to targeted computers. Trojan:Win32/Tobfy.I locks the targeted computer and displays a localized webpage covering the desktop of the compromised PC. The fake full-screen pop-up image/alert created and displayed by Trojan:Win32/Tobfy.I pretends to be from a legitimate institution and states that the computer has been locked because the PC owner has been downloading and storing illegitimate material. Trojan:Win32/Tobfy.I downloads the webpages from the certain servers. Trojan:Win32/Tobfy.I demands a ransom to be paid to unlock the computer and avoid arrest. Trojan:Win32/Tobfy.I may spread via drive-by downloads. PC users may also inadvertently download Trojan:Win32/Tobfy.I into the computer, as it has been known to masquerade as the installer for certain popular programs, such as 'Skype.exe', 'uTorrent.exe', 'Opera.exe' and 'ICQ.exe'. Trojan:Win32/Tobfy.I may create the certain registry entry so that it can run automatically every time Windows is started. Trojan:Win32/Tobfy.I closes the program whose windows have the title 'Program manager'. This is the window title for a file named 'progman.exe'. Trojan:Win32/Tobfy.I takes webcam snapshots.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "svñhîst" = "[malware file name]"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "svñhîst" = "[malware file name]"
Loading...