Home Malware Programs Trojans Trojan.Tibs

Trojan.Tibs

Posted: February 26, 2007

Threat Metric

Threat Level: 9/10
Infected PCs: 497
First Seen: July 24, 2009
Last Seen: May 6, 2024
OS(es) Affected: Windows

ScreenshotTrojan.Tibs is a Trojan Downloader program that is related to the VXGame Trojan. Once Trojan.Tibs is executed on your computer, it will connect to the Internet and download additional malware. Trojan.Tibs may also generate large numbers of popup adverts, and it will also attempt to bypass the Windows Firewall. Trojan.Tibs program is a security risk, and should be removed immediately to protect your personal data. Fake email greeting cards are infected with trojans. Beware of strangers sending greeting cards.

Recently, greeting cards via e-mail are forcing trojans like Trojan.Tibs into people's inboxes. You may be infected with Trojan.Tibs if the file ecard.exe appears on your computer.

What is a Greeting Card Email Spam?

A greeting card e-mail spam is a new method in which spammers are tricking e-mail recipients into downloading trojans such as Trojan.Tibs. The spammed e-mail subject line says you’ve received a greeting card from a "friend," "neighbour," or "family member" with a link in the message body that sends the recipient to a website that forces the trojan onto the computer. Once installed, Trojan.Tibs opens a cocktail of browser and application exploits that attempt to download malware on your computer.

Subjects that appear on the spammed e-mails:

You've received a greeting card from a admirer!
You've received a greeting card from a class mate!
You've received a greeting card from a colleague!
You've received a greeting card from a family member!
You've received a greeting card from a friend!
You've received a greeting card from a mate!
You've received a greeting card from a neighbor!
You've received a postcard from a Worshipper!
You've received a greeting card from a School friend!
You've received a greeting card from a School-mate!
You've received a postcard from a Partner!

Aliases

W32/FakeAV.NMUT!tr [Fortinet]Trojan.Win32.FakeAV [Ikarus]Artemis!C5D5EBE9A8AA [McAfee-GW-Edition]TROJ_GEN.RC1CDGG [TrendMicro]TR/Crypt.XPACK.Gen2 [AntiVir]Trojan.DownLoader6.29653 [DrWeb]Trojan.Win32.FakeAV.nmut [Kaspersky]FakeAlert-PJ.gen.br [McAfee]Generic24.HJY [AVG]W32/FakeAV.EFL!tr [Fortinet]Backdoor.Win32.Cycbot [Ikarus]Win-Trojan/Jorik.Gen [AhnLab-V3]Backdoor:Win32/Cycbot.B [Microsoft]Win32/FakeAlert.J!generic [eTrust-Vet]FakeAlert-BlueFAV [McAfee-GW-Edition]
More aliases (574)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\dfrgsnapnt.exe File name: dfrgsnapnt.exe
Size: 470.86 KB (470864 bytes)
MD5: 60d5974a9f7adefe88beb64cf36c5ff1
Detection count: 351
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: November 15, 2010
stdrun5.exe, kernels88.exe File name: stdrun5.exe, kernels88.exe
Size: 9.49 KB (9493 bytes)
MD5: f8f21e979d9c951871094924c76aa3ac
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
YUR1D.exe File name: YUR1D.exe
Size: 74.75 KB (74752 bytes)
MD5: ad6344c62a0a04cda2fb5a16cf67e32d
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: July 13, 2021
YURC7.exe File name: YURC7.exe
Size: 29.18 KB (29184 bytes)
MD5: ebf8fa662798fab0c74da4b9a2803509
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
ctfmona.exe File name: ctfmona.exe
Size: 101.37 KB (101376 bytes)
MD5: 850de4050fefcbbb6f3e631020557ea6
Detection count: 80
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 24, 2010
_ex-08.exe File name: _ex-08.exe
Size: 410.62 KB (410624 bytes)
MD5: 7ff13e8b8a926d9475a2f9664a24b982
Detection count: 76
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
%TEMP%\upd32.exe File name: upd32.exe
Size: 649.47 KB (649472 bytes)
MD5: 4bb777af901ea822ac2eb3e57eab96dd
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: December 1, 2010
vedxga1me4t1.exe File name: vedxga1me4t1.exe
Size: 20.98 KB (20988 bytes)
MD5: e7530034e176b383be308e1b1dcb8fbc
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 8, 2010
alt.exe.exe File name: alt.exe.exe
Size: 133.92 KB (133926 bytes)
MD5: 420bc1dc37d68f0eec10abbaf93b8a3f
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
fun[1].exe File name: fun[1].exe
Size: 7.97 KB (7974 bytes)
MD5: de17ad2b30e950d818795f72fe099303
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
ev1kn3tsv5so.exe File name: ev1kn3tsv5so.exe
Size: 336.89 KB (336896 bytes)
MD5: f8011111392c883fce861eaa802e6f0c
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
ntdll64.dll File name: ntdll64.dll
Size: 46.08 KB (46080 bytes)
MD5: bdf7a98d806558528ad4459fc655d552
Detection count: 40
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
tmp019.exe File name: tmp019.exe
Size: 54.27 KB (54272 bytes)
MD5: e7634f2119ae0d10b8eb186e7596a6d6
Detection count: 25
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 18, 2010
install.exe~ File name: install.exe~
Size: 90.92 KB (90923 bytes)
MD5: a5ec91c21e86259114122505364f1a98
Detection count: 24
Mime Type: unknown/exe~
Group: Malware file
Last Updated: December 11, 2009
ecard.exe File name: ecard.exe
Size: 138.96 KB (138967 bytes)
MD5: b1efd023ad4a6bfce05961073354be64
Detection count: 22
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
%APPDATA%\Protector-pghq.exe File name: Protector-pghq.exe
Size: 2.53 MB (2539520 bytes)
MD5: c5d5ebe9a8aa67ff6a65bbb09c85194c
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: September 25, 2012
YUR39.exe File name: YUR39.exe
Size: 24.06 KB (24064 bytes)
MD5: 6ae268e7281a50c2a5ae35973c8f3f10
Detection count: 11
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
maxpaynowti1.exe File name: maxpaynowti1.exe
Size: 25.97 KB (25970 bytes)
MD5: 45514abe853880e3e5925f9fe999051d
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
Sys1.exe File name: Sys1.exe
Size: 24.06 KB (24064 bytes)
MD5: 2877bd6b89dad0246f082c95ce73d286
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009

More files

Related Posts

One Comment

  • Beverly Harris says:

    Thanks so much for these instructions and recommendations. I have been trying to remove this spyware for days; no matter what I did, it kept coming back. Though I was skeptical, I finally downloaded and purchased Spyhunter. I scanned the system with Spyhunter but it had been unable to remove this virus "Trojan.Tibs." Without your instructions for un-registering the problem dll, I would still be floundering around.

Loading...