Home Malware Programs Worms Worm:VBS/Tibni.A

Worm:VBS/Tibni.A

Posted: September 2, 2015

Threat Metric

Ranking: 14,903
Threat Level: 5/10
Infected PCs: 998
First Seen: September 2, 2015
Last Seen: October 11, 2023
OS(es) Affected: Windows

Worm:VBS/Tibni.A is aggressive and stubborn malware, which may provide its operators with remote access to the infected systems. Most often this harmful application enters with the help of compromised removable storage devices such as USBs and external hard drives. Some users may get the impression that these devices are empty, but you should know that Worm:VBS/Tibni.A can hide its presence pretty well. After an infected USB connects to your PC, the main executable file of this malware will immediately copy itself to the system. A particularly unpleasant trait of the computer worms is that they can replicate themselves. This fact means that if your machine belongs to a network, the other computers may also get infected. Worm:VBS/Tibni.A overwrites HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, which is the registry key that allows programs to launch automatically. As a result, this malware will start working simultaneously with the system startup. You should know that Worm:VBS/Tibni.A also takes control of the available web browsers, including Google Chrome, Mozilla Firefox and Internet Explorer. The worm forces them to load various sites in the background – for example, ftp.bahaty.com. From this platform, it downloads a malicious file named micropro.exe. The people behind this harmful program can use it to steal files from your hard drives. If you log into your online accounts when your PC is infected, the hackers may obtain your passwords. It is not easy to detect the presence of Worm:VBS/Tibni.A. Very often, the existence of particular registry subkeys is the only sign. You should scan your system regularly with powerful anti-malware software to make sure you are not infected with such dangerous cyber threats.

Loading...