Home Malware Programs Trojans Trojan:Win32/Tobfy.N

Trojan:Win32/Tobfy.N

Posted: February 13, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 81
First Seen: February 13, 2013
OS(es) Affected: Windows

Trojan:Win32/Tobfy.N is a ransomware Trojan that locks the affected computer and displays a fake full-screen pop-up image/alert on the desktop of the PC. The bogus Federal Bureau of Investigation (FBI) notification delivered by Trojan:Win32/Tobfy.N blames a computer user for the supposed storage of illegal material and breach of laws. Trojan:Win32/Tobfy.N demands a ransom from a victim to be paid via Green Dot MoneyPak to unlock the PC and avoid imprisonment. Trojan:Win32/Tobfy.N may make continuous changes to the infected computer system that make it difficult for a computer user to download, install, run, or update anti-virus programs. Trojan:Win32/Tobfy.N may be installed on the compromised machine by other PC threats, or it may proliferate via drive-by downloads from a hacked website. When executed, Trojan:Win32/Tobfy.N drops a malicious file and modifies the registry entry so that it can run its copy automatically every time you start Windows.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\ifgxpers.exe File name: ifgxpers.exe
Size: 69.62 KB (69624 bytes)
MD5: bedf23926c3911bd4b3b31a983ea0dd1
Detection count: 39
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: February 14, 2013
file.exe File name: file.exe
Size: 75.52 KB (75527 bytes)
MD5: d0caf469608b419145e91378c3f5dd36
Detection count: 1
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 14, 2013

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Adobe ARM" = "%APPDATA%\ifgxpers.exe"
Loading...