Trojan.Tobfy Removal Guide

Do you know what Trojan.Tobfy is?

Trojan.Tobfy is a malicious Windows infection which drops dangerous files into various locations on your operating system, including %WINDIR%, %USERPROFILE%, %APPDATA% and %TEMP%. Most Windows users will not know about the existence of the vicious infection until it initiates a computer lock-down and activates a misleading notification, also known as a ransomware virus. Schemers have done a good job at creating these malicious ransomware infections because they can target specific countries with notifications represented in different languages and referring to different law enforcement agencies. As you may already know, the main objective of this infection is to trick you into paying fines for completely bogus cyber crimes. Of course, to unlock the PC and ensure secure Windows running, you need to remove the lock-down and delete Trojan.Tobfy. Continue reading to learn more about its removal.

Most of the malignant Trojan.Tobfy files have randomly generated names (e.g. fastsrch.dll, jrttaf.exe, an2ans.exe) which should make it much easier for you to detect and delete them. Unfortunately, these files enter the computer using clandestine security backdoors, run surreptitiously and act before you even recognize their existence. Overall, their main task is to reconfigure the Windows Registry, so that access to the desktop would be removed, and to display a fictional notification. Please see a few different extracts:

Your PC is blocked due to at least one of the reasons specified below

Achtung! Ihr computer ist aus einem oder mehreren der unten aufgeführten Gründe gesperrt.

Fines may only be paid within 72 hours after the infringement. As soon as 72 hours elapse, the possibility to pay the fine expires, and a criminal case is initiated against you automatically within the next 72 hours! The amount of fine is CAD 100.

Der Betrag der Strafzahlung beläuft sich auf €100 Ukash oder Paysafecard.

To unblock the computer, you must pay the fine through MoneyPak of $200.

The accusations you are presented with may span from the downloading of illegal pirated files to the distribution of pornographic videos or terrorist content spam emails. If your PC has been locked with a suspicious alert supposedly sent to you by Police, there is no doubt that your Windows system has been infected with one of the Trojan.Tobfy ransomware infections. You may recognize them by such names as PCeU Infection, Interpol Department of Cybercrime Virus, GVU Virus, Metropolitan Police Virus, etc.

As soon as you find your desktop locked, you need to remove Trojan.Tobfy. This is the only way to restore Windows functionality and get back to regular computer tasks. We do not recommend proceeding with manual removal procedures because they are complicated and can lead to further obstructions. However, the instructions below will help you unlock the PC and install automatic removal tool SpyHunter which will delete the Trojan and any other running infections, and grant full-time protection services in the future.

How to remove Trojan.Tobfy?

Delete from Windows 8:

  1. Tap the Windows key to access the Metro UI start screen.
  2. Move the cursor to the bottom right of the screen and click Settings.
  3. Select Change PC Settings, click General, navigate to Advanced Startup and click Start now.
  4. Click Troubleshoot and then Advanced Options.
  5. From the menu select Startup Settings and click Restart.
  6. Once the Startup Setting menu shows up again tap F5 (Safe Mode with Networking).
  7. Download SpyHunter from .
  8. Install the automatic malware detection and removal tool.
  9. Perform a full system scan, delete found infections (Fix Threats) and restart the computer.

Delete from Windows Vista and Windows 7:

  1. Restart the PC.
  2. As soon as BIOS loads up start tapping F8.
  3. Using arrow keys select Safe Mode with Networking and tap Enter.
  4. Download and install SpyHunter to delete the malicious Trojan.

Delete from Windows XP:

  1. Firstly restart the PC and, as soon as BIOS loads up, start tapping F8.
  2. Use arrow keys on the keyboard to select Safe Mode with Networking. Tap Enter.
  3. Click YES on the Desktop alert.
  4. Download the automatic spyware removal tool SpyHunter.
  5. Navigate to the left of the Task Bar and click on Start.
  6. Launch RUN, enter msconfig and click OK.
  7. Click on the Startup tab, select Disable All and click OK.
  8. Restart the computer (normally).
  9. Install the application and delete existing infections as soon as possible.

In non-techie terms:

Trojan.Tobfy is a clandestine Trojan which will be infiltrated onto your computer in order to initiate a deceitful ransomware scam. The infection might lock-down the computer and present bogus statements about your virtual activity. Ignore any information presented to you by the ransomware and follow the instructions above to find and delete Trojan.Tobfy.

Aliases: Tobfy.