Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | June 2008 (4.30) |
| Protection available since | 17 April 2008 22:53:40 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
When first run Troj/Tibs-UF copies itself to:
<System>\wind32.exe
and creates the following file:
<System>\dll<random characters>.exe - at the time of writing, is a 0 byte file. This file can be deleted safely.
Troj/Tibs-UF creates the following registry entry to start itself:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
System
<System>\wind32.exe
and attempts to avoid process termination via:
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1
