









 |
W32/Tibs.HY Trojan
| Name |
W32/Tibs.HY Trojan |
| Aliases |
Packed.Win32.Tibs.hy, Troj/Outpost-A, SHeur.APRM, Trojan/Tibs.hy |
| Discovered on |
February 04, 2008 |
Virus Information - W32/Tibs.HY Trojan:
W32/Tibs.HY is a trojan. The trojan will infect Windows systems.
Upon execution, it drops the following files:
kernelwind64.exe in Windows System folder
dllgh8jkd1q8.exe in Windows System folder.
The trojan modifies registry at the following location to load itself during each startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\System
The trojan changes the firewall policies of the local computer.
It also disables the Windows Task Manager.

|