Threat Search: 

ThreatExpert's Statistics for Worm:Win32/Tofam!rts [Microsoft]:

Worm:Win32/Tofam!rts [Microsoft] is also known as:
Threat AliasNumber of Incidents
Email-Worm.Win32.Brontok [Ikarus]7
Email-Worm.Win32.Brontok.q [Kaspersky Lab]6
Mal/EncPk-BA [Sophos]6
W32/Rontokbro.gen@MM [McAfee]6
I-Worm.Brontok.Gen.2 [PC Tools]4
Suspicious.MH690 [Symantec]4
Win-Trojan/Brontok.45400 [AhnLab]4
W32.Rontokbro@mm [Symantec]3
Email-Worm.Brontok.Q [PC Tools]2
Win32/Brontok.worm.42089 [AhnLab]2
Email-Worm.Win32.Brontok.dd [Kaspersky Lab]1
Mal/Generic-A [Sophos]1
Mal/Sohana-A [Sophos]1
W32/YahLover.worm.gen [McAfee]1

Worm:Win32/Tofam!rts [Microsoft] has the following possible country of origin:
OriginNumber of Incidents
United Kingdom1

Worm:Win32/Tofam!rts [Microsoft] is known to be created as:
%AppData%\microsoft\dfreeze.exe
%CommonDocuments%\dfreeze.exe
%System%\sysdriver.sys
%Windir%\help\safeboot.exe
%Windir%\missau.exe
%Windir%\system\sysdriver.sys
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonDocuments% is a variable that refers to the file system directory that contains documents that are common to all users. A typical paths is C:\Documents and Settings\All Users\Documents.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.