









 |
W32/Tibs.IC Trojan
| Name |
W32/Tibs.IC Trojan |
| Aliases |
WORM_NUWAR.AR, Zhelatin.TQ |
| Discovered on |
Feb 14, 2008 |
Virus Information - W32/Tibs.IC Trojan:
W32/Tibs.IC is a trojan. The trojan will infect Windows systems.
Upon execution, it drops diperito[random characters].sys in Windows System folder.
it also drops a non malicious file diperto.ini in Windows System folder.
It registers itself as a windows service by name diperto[random characters] to load itself during each startup. It modifies the registry at the following location to achieve the same.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services 
|