Ransom

Ransom:Win32/Tobfy.F removal instruction

Malware Removal

The Ransom:Win32/Tobfy.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Tobfy.F virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine Ransom:Win32/Tobfy.F?


File Info:

crc32: 8302BC38
md5: 2045ea47e45a5dbec997369ebb674131
name: 2045EA47E45A5DBEC997369EBB674131.mlw
sha1: fef4fa97645eb2378451800a1b966ee1413a98f8
sha256: 8122cfd49ae01ddfdae52095b03d23fa8417ad5098be1fe888c6a826531e02b8
sha512: 7488d5bf3696efc2d3e3fdbe09d59219025d882fc86fcc8d8d4bb16c0fffe80f4f2c79e38c5b4577688d2915aa9c41713912aad69a7345ed1913aab7c80d4636
ssdeep: 1536:P29osBIlbqQpr1D/7eHTxZLUT5Wz0vkzsG8GEt4BZ8f:P29IlbqQ3eXUlW4k4tYGf
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Tobfy.F also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop4.9433
CynetMalicious (score: 85)
ALYacGen:Variant.Symmi.8604
CylanceUnsafe
ZillyaTrojan.Buzus.Win32.108667
SangforPUP.Win32.Symmi.8604
AlibabaVirTool:Win32/Obfuscator.40d95a6a
Cybereasonmalicious.7e45a5
SymantecTrojan.Shylock
ESET-NOD32a variant of Win32/Injector.YNE
APEXMalicious
AvastWin32:Cryptor
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.8604
NANO-AntivirusTrojan.Win32.YNE.cxxqyf
ViRobotTrojan.Win32.A.Buzus.85504.B
MicroWorld-eScanGen:Variant.Symmi.8604
TencentWin32.Trojan.Buzus.mft
Ad-AwareGen:Variant.Symmi.8604
SophosML/PE-A + Mal/EncPk-AHQ
ComodoTrojWare.Win32.PWS.ZBot.AAA@4sq88d
BitDefenderThetaGen:NN.ZexaF.34628.fGW@ay!a72ei
VIPRETrojan.Win32.Encpk.ahq (v)
TrendMicroTROJ_RANSOM.SMWX
McAfee-GW-EditionPWS-Zbot.gen.apx
FireEyeGeneric.mg.2045ea47e45a5dbe
EmsisoftGen:Variant.Symmi.8604 (B)
WebrootW32.Rogue.Gen
AviraTR/Dropper.Gen7
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Tobfy.F
AegisLabTrojan.Win32.Zbot.lEHF
GDataGen:Variant.Symmi.8604
TACHYONTrojan/W32.Buzus.85504.BG
McAfeePWS-Zbot.gen.apx
MAXmalware (ai score=100)
VBA32Worm.Dorkbot.1312
PandaTrj/OCJ.C
TrendMicro-HouseCallTROJ_RANSOM.SMWX
RisingRansom.Tobfy!8.339 (CLOUD)
YandexTrojan.Injector!VK64Kjfy7PM
IkarusTrojan-Ransom.Foreign
MaxSecureTrojan.Malware.4845933.susgen
FortinetW32/Ransom.AAX!tr
AVGWin32:Cryptor
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.b65

How to remove Ransom:Win32/Tobfy.F?

Ransom:Win32/Tobfy.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment