Threat Search: 

ThreatExpert's Statistics for Tibs-Packed [McAfee]:

Tibs-Packed [McAfee] is also known as:
Threat AliasNumber of Incidents
Backdoor.Frauder!sd6 [PC Tools]1,403
Mal/Dorf-E [Sophos]1,394
Trojan:Win32/Tibs.IH [Microsoft]1,013
Virus.Win32.Tipa [Ikarus]899
TrojanDropper:Win32/Nuwar [Microsoft]405
Troj/FakeVir-GJ [Sophos]390
Trojan.Win32.Tibs [Ikarus]365
Trojan.Zlob [Symantec]329
Backdoor.Win32.Frauder.ls [Kaspersky Lab]266
Trojan.DL.Zlob.Gen!Pac.46 [PC Tools]246
Backdoor.Win32.Frauder.lm [Kaspersky Lab]234
Backdoor.Win32.Frauder.ln [Kaspersky Lab]234
Backdoor.Win32.Frauder.lo [Kaspersky Lab]234
Backdoor.Win32.Frauder.lp [Kaspersky Lab]234
Backdoor.Win32.Frauder.lq [Kaspersky Lab]234
Backdoor.Win32.Frauder.lr [Kaspersky Lab]234
Trojan Horse [Symantec]156
Possible_Nucrp-6 [Trend Micro]115
Bloodhound.Unknown [Symantec]109
Downloader [Symantec]96
Trojan.Tibs.Gen!Pac.132 [PC Tools]89
Trojan.Packed.13 [Symantec]68
Trojan.Tibs.Gen!Pac.146 [PC Tools]44
WORM_NUCRP.GEN [Trend Micro]44
Mal/TibsPak [Sophos]43
Email-Worm.Zhelatin [PC Tools]41
TrojanDownloader:Win32/Cbeplay.E [Microsoft]35
WORM_NUCRYPT.GEN [Trend Micro]34
Trojan:Win32/Tibs.J [Microsoft]30
Mal/EncPk-DA [Sophos]28
Downloader.MisleadApp [Symantec]27
Trojan:Win32/Tibs.FZ [Microsoft]23
Trojan.Erotpics [Symantec]22
Trojan-Downloader.Win32.Tibs.tc [Kaspersky Lab]20
Mal/Generic-A [Sophos]19
Trojan.Tibs.Gen!Pac.G [PC Tools]19
Mal/EncPk-DA, Mal/TibsPak [Sophos]17
Trojan.Tibs.Gen!Pac.A [PC Tools]17
Trojan.Tibs.Gen!Pac.C [PC Tools]14
TrojanDownloader:Win32/Cbeplay.I [Microsoft]14
Backdoor.Win32.Frauder.nb [Kaspersky Lab]12
Email-Worm.Win32.Zhelatin.nc [Kaspersky Lab]12
Mal/TibsPk-A, Mal/TibsPk-D [Sophos]12
Trojan-Downloader.Win32.Tibs.yn [Ikarus]12
Trojan-Downloader.Win32.Tibs.yn [Kaspersky Lab]12
WORM_NUWAR.ARK [Trend Micro]12
WORM_ZHELATI.AIR [Trend Micro]12
Email-Worm.Win32.Zhelatin.ml [Kaspersky Lab]11
Email-Worm.Win32.Zhelatin.pd [Kaspersky Lab]11
Possible_Nucrp-5 [Trend Micro]10
Trojan-Downloader.MisleadApp!sd6 [PC Tools]10
Email-Worm.Win32.Zhelatin.oc [Kaspersky Lab]9
Trojan.Tibs.Gen!Pac.144 [PC Tools]9
Trojan.Tibs.Gen!Pac.147 [PC Tools]9
Trojan:Win32/Tibs.gen!G [Microsoft]8
Email-Worm.Win32.Zhelatin.lj [Kaspersky Lab]7
Mal/Dorf-F [Sophos]7
Trojan.DL.Zlob.IXF [PC Tools]7
Trojan.DL.Zlob.IXH [PC Tools]7
Trojan.Erotpics!sd6 [PC Tools]7
Trojan.Pandex [Symantec]7
Trojan:Win32/Tibs.gen!ldr [Microsoft]7
WORM_NUWAR.ARI [Trend Micro]7
Backdoor.Win32.Frauder.ol [Kaspersky Lab]6
Packed.Win32.Tibs.cy [Kaspersky Lab]6
TROJ_DLOADE.DGM [Trend Micro]6
TROJ_ZLOB.APQ [Trend Micro]6
TROJ_ZLOB.DAM [Trend Micro]6
TROJ_ZLOB.EVR [Trend Micro]6
Trojan.DL.DR.Zirit.C [PC Tools]6
Trojan.Fakeavalert [Symantec]6
Trojan:Win32/Tibs.EU [Microsoft]6
Trojan-Downloader.Win32.Tibs.ry [Kaspersky Lab]6
Trojan-Downloader.Win32.Tibs.zz [Kaspersky Lab]6
TrojanDownloader:Win32/Tibs [Microsoft]6
Backdoor.Trojan [Symantec]5
Email-Worm.Zhelatin!sd5 [PC Tools]5
Packed.Generic.126 [Symantec]5
Packed.Win32.Tibs [Ikarus]5
Packed.Win32.Tibs.eu [Kaspersky Lab]5
Possible_Nucrp-4 [Trend Micro]5
TROJ_TIBS.BYJ [Trend Micro]5
TROJ_TIBS.CY [Trend Micro]5
Trojan-Downloader.Win32.Exchanger [Ikarus]5
Trojan-Downloader.Win32.Tibs.ta [Kaspersky Lab]5
Backdoor.Win32.Frauder.ob [Kaspersky Lab]4
Backdoor.Win32.Frauder.oc [Kaspersky Lab]4
Backdoor.Win32.Frauder.oe [Kaspersky Lab]4
Backdoor.Win32.Frauder.of [Kaspersky Lab]4
Backdoor.Win32.Frauder.og [Kaspersky Lab]4
Email-Worm.Win32.Zhelatin.hc [Kaspersky Lab]4
Email-Worm.Win32.Zhelatin.nd [Kaspersky Lab]4
Email-Worm.Win32.Zhelatin.xd [Kaspersky Lab]4
Email-Worm.Win32.Zhelatin.xz [Kaspersky Lab]4
Exploit.Win32.IMG-WMF.je [Kaspersky Lab]4
Mal/Dorf-E, Mal/Dorf-D, Mal/TibsPak [Sophos]4
TROJ_CFLY.A [Trend Micro]4
TROJ_MULP.DP [Trend Micro]4
TROJ_TIBS.AVP [Trend Micro]4
TROJ_ZLOB.YT [Trend Micro]4

Tibs-Packed [McAfee] has the following possible countries of origin:
OriginNumber of Incidents
Russian Federation67
Sweden1

Tibs-Packed [McAfee] is known to be created as:
%ProgramFiles%\ofb1\_install.exe
%ProgramFiles%\pchealthcenter\0.exe
%ProgramFiles%\pchealthcenter\1.exe
%ProgramFiles%\pchealthcenter\2.exe
%ProgramFiles%\pchealthcenter\3.exe
%ProgramFiles%\pchealthcenter\4.exe
%ProgramFiles%\pchealthcenter\5.exe
%ProgramFiles%\pchealthcenter\7.exe
%System%\caevtsvc.exe
%System%\cbevtsvc.exe
%System%\ccevtsvc.exe
%System%\cdbgevtsvc.exe
%System%\kernels32.exe
%System%\kernels88.exe
%System%\kernelwind32.exe
%System%\kernelwind64.exe
%System%\maxpaynow1.exe
%System%\maxpaynowti1.exe
%System%\msiconf.exe
%System%\n2ewma1xxsv2234.exe
%System%\n2ewma1xxsv234.exe
%System%\newmaxxsv234.exe
%System%\spoolsvv.exe
%System%\wind32.exe
%System%\winds32.exe
%System%\yur1.exe
%System%\yur10.exe
%System%\yur11.exe
%System%\yur12.exe
%System%\yur13.exe
%System%\yur14.exe
%System%\yur15.exe
%System%\yur16.exe
%System%\yur17.exe
%System%\yur18.exe
%System%\yur19.exe
%System%\yur1a.exe
%System%\yur1b.exe
%System%\yur1c.exe
%System%\yur1d.exe
%System%\yur1e.exe
%System%\yur1f.exe
%System%\yur2.exe
%System%\yur20.exe
%System%\yur21.exe
%System%\yur22.exe
%System%\yur23.exe
%System%\yur24.exe
%System%\yur25.exe
%System%\yur26.exe
%System%\yur27.exe
%System%\yur28.exe
%System%\yur29.exe
%System%\yur2a.exe
%System%\yur2b.exe
%System%\yur2c.exe
%System%\yur2d.exe
%System%\yur2e.exe
%System%\yur2f.exe
%System%\yur3.exe
%System%\yur30.exe
%System%\yur31.exe
%System%\yur32.exe
%System%\yur33.exe
%System%\yur34.exe
%System%\yur35.exe
%System%\yur36.exe
%System%\yur37.exe
%System%\yur38.exe
%System%\yur39.exe
%System%\yur3a.exe
%System%\yur3b.exe
%System%\yur3c.exe
%System%\yur3d.exe
%System%\yur3e.exe
%System%\yur3f.exe
%System%\yur4.exe
%System%\yur40.exe
%System%\yur41.exe
%System%\yur42.exe
%System%\yur43.exe
%System%\yur44.exe
%System%\yur45.exe
%System%\yur46.exe
%System%\yur47.exe
%System%\yur48.exe
%System%\yur49.exe
%System%\yur4a.exe
%System%\yur4b.exe
%System%\yur4c.exe
%System%\yur4d.exe
%System%\yur4e.exe
%System%\yur4f.exe
%System%\yur5.exe
%System%\yur50.exe
%System%\yur51.exe
%System%\yur52.exe
%System%\yur53.exe
%System%\yur54.exe
%System%\yur55.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).