Skip to main content
Skip to main content
Published Nov 29, 2007 | Updated Sep 15, 2017

VirTool:WinNT/Tibs.gen!A

Detected by Microsoft Defender Antivirus

Aliases: Win-Trojan/AVKiller.7968 (AhnLab) W32/Tibs.XA (Command) Downloader.Tibs (AVG) Win32/Rootkit.Agent.NDD (ESET) Packed.Win32.Tibs.ap (Kaspersky) W32/Nuwar.sys (McAfee) Troj/Dorf-P (Sophos) Trojan-Proxy.Win32.Lager.gen (Sunbelt Software)

Summary

VirTool:WinNT/Tibs.gen!A is generic detection for drivers used across multiple pieces of malware affiliated with the 'Tibs' malware distribution network. WinNT/Tibs malware uses rootkit methods to hide its presence on an infected computer.
Manual removal is not recommended for this threat. Use Microsoft Security Essentials or another up-to-date scanning and removal tool to detect and remove this threat and other unwanted software from your computer. For more information on Microsoft security products, see http://www.microsoft.com/protect/products/computer/default.mspx.
Follow us