Trojan

Trojan:Win32/Tibs!B removal

Malware Removal

The Trojan:Win32/Tibs!B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Tibs!B virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/Tibs!B?


File Info:

name: 448F5509368B47924837.mlw
path: /opt/CAPEv2/storage/binaries/34f5f9bdb31367fc38ab50f59450996621a7545ad81e368e6405080b2e0daac7
crc32: F36F7062
md5: 448f5509368b479248373eb642df6fef
sha1: 1b25fe2db3d69f473f62bd8740b02811fff219aa
sha256: 34f5f9bdb31367fc38ab50f59450996621a7545ad81e368e6405080b2e0daac7
sha512: bcbfb3f245185f5f15d3db8fa4506df8728998ebea9240a6e1de7564358446640ad61885747a51210e5374ea5567fc81226dcd244e977a2f0384f62473cd639e
ssdeep: 768:kWkjjpPqqG79F/tGF9TD3w1201HW/FT6E7lixH6KfKbW/fRo:kWkjjFJweFhcUy2/FTHwFS8S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150F2D09B6FEF61F0FDCE41BB91D6D29CA231412513512A627C6CCAB283717787029DD2
sha3_384: b63a28ac7307167bcc778199d9696f63f9ebed2dd903a40c3ecd393402afe03e8525011092f037322743827ed72c4ee1
ep_bytes: c8000000ba0132b9f681c2ffff870952
timestamp: 2007-01-26 14:47:39

Version Info:

0: [No Data]

Trojan:Win32/Tibs!B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Tibs.a!c
DrWebTrojan.Packed.10
MicroWorld-eScanTrojan.Peed.Gen
FireEyeGeneric.mg.448f5509368b4792
CAT-QuickHealTrojan.Tibs.jr
SkyhighBehavesLike.Win32.Generic.nc
Cylanceunsafe
VIPRETrojan.Peed.Gen
SangforDownloader.Win32.Tibs.Vgc3
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.Peed.Gen
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
BitDefenderThetaAI:Packer.A15EB64D1E
SymantecTrojan.Packed.13
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Nuwar.gen
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.1326-1
KasperskyTrojan-Downloader.Win32.Tibs.jr
AlibabaTrojanDownloader:Win32/Vxidl.4376a21f
NANO-AntivirusTrojan.Win32.ULPM.bahgrn
RisingWorm.Mail.Zhelatin.GEN (CLASSIC)
SophosMal/EncPk-F
F-SecureTrojan.TR/Crypt.ULPM.Gen
ZillyaDownloader.Tibs.Win32.11677
TrendMicroWORM_NUCRP.GEN
Trapminemalicious.high.ml.score
EmsisoftTrojan.Peed.Gen (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
VaristW32/Trojan.OVAA-5947
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Downloader]/Win32.Tibs
KingsoftWin32.Troj.Undef.a
MicrosoftTrojan:Win32/Tibs.gen!B
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Peed.Gen
ZoneAlarmTrojan-Downloader.Win32.Tibs.jr
GDataTrojan.Peed.Gen
GoogleDetected
AhnLab-V3Win-Trojan/MalPatched.Gen
McAfeeDownloader-BAI.gen.b
DeepInstinctMALICIOUS
VBA32Trojan-Downloader.Revelation.Tibs.B
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_NUCRP.GEN
TencentWin32.Trojan-Downloader.Tibs.Cdhl
IkarusTrojan-Downloader.Win32.Tibs.jr
MaxSecureTrojan.Malware.1386273.susgen
FortinetW32/Tibs.gen
AVGWin32:Tibs-AJT [Trj]
Cybereasonmalicious.db3d69
AvastWin32:Tibs-AJT [Trj]

How to remove Trojan:Win32/Tibs!B?

Trojan:Win32/Tibs!B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment