Trojan.Tibs
Posted: February 26, 2007
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
| Threat Level: | 9/10 |
|---|---|
| Infected PCs: | 497 |
| First Seen: | July 24, 2009 |
|---|---|
| Last Seen: | May 6, 2024 |
| OS(es) Affected: | Windows |
Trojan.Tibs is a Trojan Downloader program that is related to the VXGame Trojan. Once Trojan.Tibs is executed on your computer, it will connect to the Internet and download additional malware. Trojan.Tibs may also generate large numbers of popup adverts, and it will also attempt to bypass the Windows Firewall. Trojan.Tibs program is a security risk, and should be removed immediately to protect your personal data. Fake email greeting cards are infected with trojans. Beware of strangers sending greeting cards.
Recently, greeting cards via e-mail are forcing trojans like Trojan.Tibs into people's inboxes. You may be infected with Trojan.Tibs if the file ecard.exe appears on your computer.
What is a Greeting Card Email Spam?
A greeting card e-mail spam is a new method in which spammers are tricking e-mail recipients into downloading trojans such as Trojan.Tibs. The spammed e-mail subject line says you’ve received a greeting card from a "friend," "neighbour," or "family member" with a link in the message body that sends the recipient to a website that forces the trojan onto the computer. Once installed, Trojan.Tibs opens a cocktail of browser and application exploits that attempt to download malware on your computer.
Subjects that appear on the spammed e-mails:
You've received a greeting card from a admirer!
You've received a greeting card from a class mate!
You've received a greeting card from a colleague!
You've received a greeting card from a family member!
You've received a greeting card from a friend!
You've received a greeting card from a mate!
You've received a greeting card from a neighbor!
You've received a postcard from a Worshipper!
You've received a greeting card from a School friend!
You've received a greeting card from a School-mate!
You've received a postcard from a Partner!
Aliases
More aliases (574)
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:%TEMP%\dfrgsnapnt.exe
File name: dfrgsnapnt.exeSize: 470.86 KB (470864 bytes)
MD5: 60d5974a9f7adefe88beb64cf36c5ff1
Detection count: 351
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: November 15, 2010
stdrun5.exe, kernels88.exe
File name: stdrun5.exe, kernels88.exeSize: 9.49 KB (9493 bytes)
MD5: f8f21e979d9c951871094924c76aa3ac
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
YUR1D.exe
File name: YUR1D.exeSize: 74.75 KB (74752 bytes)
MD5: ad6344c62a0a04cda2fb5a16cf67e32d
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: July 13, 2021
YURC7.exe
File name: YURC7.exeSize: 29.18 KB (29184 bytes)
MD5: ebf8fa662798fab0c74da4b9a2803509
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
ctfmona.exe
File name: ctfmona.exeSize: 101.37 KB (101376 bytes)
MD5: 850de4050fefcbbb6f3e631020557ea6
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 24, 2010
_ex-08.exe
File name: _ex-08.exeSize: 410.62 KB (410624 bytes)
MD5: 7ff13e8b8a926d9475a2f9664a24b982
Detection count: 76
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
%TEMP%\upd32.exe
File name: upd32.exeSize: 649.47 KB (649472 bytes)
MD5: 4bb777af901ea822ac2eb3e57eab96dd
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 1, 2010
vedxga1me4t1.exe
File name: vedxga1me4t1.exeSize: 20.98 KB (20988 bytes)
MD5: e7530034e176b383be308e1b1dcb8fbc
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 8, 2010
alt.exe.exe
File name: alt.exe.exeSize: 133.92 KB (133926 bytes)
MD5: 420bc1dc37d68f0eec10abbaf93b8a3f
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
fun[1].exe
File name: fun[1].exeSize: 7.97 KB (7974 bytes)
MD5: de17ad2b30e950d818795f72fe099303
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
ev1kn3tsv5so.exe
File name: ev1kn3tsv5so.exeSize: 336.89 KB (336896 bytes)
MD5: f8011111392c883fce861eaa802e6f0c
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
ntdll64.dll
File name: ntdll64.dllSize: 46.08 KB (46080 bytes)
MD5: bdf7a98d806558528ad4459fc655d552
Detection count: 40
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
tmp019.exe
File name: tmp019.exeSize: 54.27 KB (54272 bytes)
MD5: e7634f2119ae0d10b8eb186e7596a6d6
Detection count: 25
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 18, 2010
install.exe~
File name: install.exe~Size: 90.92 KB (90923 bytes)
MD5: a5ec91c21e86259114122505364f1a98
Detection count: 24
Mime Type: unknown/exe~
Group: Malware file
Last Updated: December 11, 2009
ecard.exe
File name: ecard.exeSize: 138.96 KB (138967 bytes)
MD5: b1efd023ad4a6bfce05961073354be64
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
%APPDATA%\Protector-pghq.exe
File name: Protector-pghq.exeSize: 2.53 MB (2539520 bytes)
MD5: c5d5ebe9a8aa67ff6a65bbb09c85194c
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: September 25, 2012
YUR39.exe
File name: YUR39.exeSize: 24.06 KB (24064 bytes)
MD5: 6ae268e7281a50c2a5ae35973c8f3f10
Detection count: 11
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
maxpaynowti1.exe
File name: maxpaynowti1.exeSize: 25.97 KB (25970 bytes)
MD5: 45514abe853880e3e5925f9fe999051d
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
Sys1.exe
File name: Sys1.exeSize: 24.06 KB (24064 bytes)
MD5: 2877bd6b89dad0246f082c95ce73d286
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
More files
Thanks so much for these instructions and recommendations. I have been trying to remove this spyware for days; no matter what I did, it kept coming back. Though I was skeptical, I finally downloaded and purchased Spyhunter. I scanned the system with Spyhunter but it had been unable to remove this virus "Trojan.Tibs." Without your instructions for un-registering the problem dll, I would still be floundering around.