Trojan-Downloader.Win32.Tibs.aw

tag:Trojan   Downloaders  

0 0

This Trojan program downloads files via the Internet without the user's knowledge or consent.

The Trojan itself is a Windows PE EXE file approximately 6KB in size, packed using FSG. The unpacked file is approximately 49KB in size.

Once launched the Trojan creates a file named "kernels64.exe" in the Windows system directory:

%System%\kernels64.exe

It then registers this file in the system registry, ensuring that the Trojan will be launched each time Windows is rebooted on the victim machine:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"System" = "%System%\kernels64.exe"

This Trojan will download, install and launch for execution other malicious programs (Pornware) on the victim machine.

©Virus-Encyclopedia.com All Rights Reserved.