Threat Database Trojans Trojan:Win32/Tobfy.N

Trojan:Win32/Tobfy.N

By ZulaZuza in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 1
First Seen: February 13, 2013
OS(es) Affected: Windows

Trojan:Win32/Tobfy.N is a ransomware Trojan that blocks the victimized PC and covers the screen with a bogus pop-up image/warning message on the screen of the computer and block a PC user from accessing the desktop. The scary alert sent by Trojan:Win32/Tobfy.N allegedly comes from the Federal Bureau of Investigation (FBI) and accuses a victim of keeping illegitimate material on a machine and, thus, violating certain laws. Trojan:Win32/Tobfy.N asks the PC user to pay a fine via Green Dot MoneyPak to restore access to the computer and evade prosecution. Trojan:Win32/Tobfy.N may make continiuous modifications to the corrupted PC that make it complicated for a PC user to download, install, execute, or update security applications. Trojan:Win32/Tobfy.N may be installed on the affected computer by other malware infections, or it may be distributed via drive-by downloads from a hijacked website. While being run, Trojan:Win32/Tobfy.N adds a malevolent file and makes modifications to the registry entry so that it can load its copy automatically whenever Windows started.

SpyHunter Detects & Remove Trojan:Win32/Tobfy.N

File System Details

Trojan:Win32/Tobfy.N may create the following file(s):
# File Name MD5 Detections
1. ifgxpers.exe bedf23926c3911bd4b3b31a983ea0dd1 1
2. ifgxpers.exe
3. file.exe 94f4204bda5a6e925c095d5e52a53ad1 0
4. file.exe fc45c1f85b23dbb68b9674ecb63e0d4c 0
5. file.exe ad45123b767a1ad23f9bd6c2d846f5af 0
6. file.exe d0caf469608b419145e91378c3f5dd36 0

Registry Details

Trojan:Win32/Tobfy.N may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "Adobe ARM" = "%APPDATA%\ifgxpers.exe"

Trending

Most Viewed

Loading...