Ransom

Ransom:Win32/Tobfy.O removal guide

Malware Removal

The Ransom:Win32/Tobfy.O is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Tobfy.O virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Executed a process and injected code into it, probably while unpacking
  • A process attempted to delay the analysis task by a long amount of time.
  • A process was set to shut the system down when terminated
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
en.kurasawa.org.ng
commerchuf.biz
kazakholop.biz

How to determine Ransom:Win32/Tobfy.O?


File Info:

crc32: 3E6CDC64
md5: a47fa79d9fdfc45aa3a9d74c6f022d77
name: A47FA79D9FDFC45AA3A9D74C6F022D77.mlw
sha1: 023bf98e13772231f6d5607aad6afebbf236337c
sha256: 688e862ff915d0f5302f849928f1a28e8cb07a3c4b066ae0584fe9de02c1633b
sha512: b389898ef9b23d4764e8f8008e46bd47f3f1bc435890783294abc0d563530445c300196f2adece6c651e9fdb1ff5296b686f329da6f11e65737495fe61c25780
ssdeep: 384:alz7fuI75NRzvyER4zKQbionS2FbaiLYAUO8HY+:Y57dmG4zKQnS2FbaiLYAy4+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2012
InternalName: dfsfds
FileVersion: 20964, 0, 0, 0
ProductName: fsdfdsdfs
ProductVersion: 36080, 0, 0, 0
FileDescription: fdsdfs
OriginalFilename: fdsfdsfds
Translation: 0x0000 0x04b0

Ransom:Win32/Tobfy.O also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0055e3f61 )
Elasticmalicious (high confidence)
DrWebTrojan.Click.64722
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.770412
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.5213
SangforRootkit.Win32.Rustock.AY
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Blocker.9e2a9ad9
K7GWSpyware ( 0055e3f61 )
Cybereasonmalicious.d9fdfc
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanClicker.Agent.NSC
APEXMalicious
AvastWin32:Rustock-AY [Rtk]
KasperskyTrojan-Ransom.Win32.Blocker.aqno
BitDefenderGen:Variant.Razy.770412
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Razy.770412
TencentWin32.Trojan.Blocker.ckhr
Ad-AwareGen:Variant.Razy.770412
SophosMal/Generic-S
ComodoMalware@#us3zo491jy7r
BitDefenderThetaAI:Packer.1B0F28401F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.mt
FireEyeGeneric.mg.a47fa79d9fdfc45a
EmsisoftGen:Variant.Razy.770412 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Tobfy.O.1
eGambitGeneric.Malware
MicrosoftRansom:Win32/Tobfy.O
ArcabitTrojan.Razy.DBC16C
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Razy.770412
McAfeeArtemis!A47FA79D9FDF
MAXmalware (ai score=99)
VBA32BScope.TrojanDropper.Sysn
PandaTrj/Genetic.gen
RisingRansom.Tobfy!8.339 (CLOUD)
YandexTrojan.Blocker!JymGRQii3CI
IkarusTrojan-Ransom.Blocker
FortinetW32/Blocker.MUD!tr
AVGWin32:Rustock-AY [Rtk]

How to remove Ransom:Win32/Tobfy.O?

Ransom:Win32/Tobfy.O removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment