Home Malware Programs Trojans Mal/TibsPk-A

Mal/TibsPk-A

Posted: March 25, 2011

Mal/TibsPk-A is a serious spyware infection that is able to create corrupt executable files on the affected system. Once active, Mal/TibsPk-A could open up the affected computer to outside criminals corrupting confidential data. Mal/TibsPk-A runs in the background and enables remote access to the corrupted computer system. Mal/TibsPk-A may also show a fraudulent Windows alert message about malware infections existing on the machine and recommends users to download or buy rogue anti-spyware software.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\1.tmp
    2 %Temp%\6.tmp
    3 %Windir%\Temp\7.tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_58DCD380HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_58DCD380\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_58DCD380\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_58DCD380HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_58DCD380\0000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_58DCD380\0000\Control
Loading...