United Kingdom
  • UK Support
  • My Account
  • Renewal Centre

Bitdefender®

  • Home
  • Home Users
  • Small Business
  • Corporate Business
  • ISPs
  • News
  • About Us
  • Partners
  • Home
  • Defense Center
  • Virus Information for - Trojan.Tibs.E
BitDefender Products
  • Home Products
  • BitDefender for your Business
About BitDefender
  • About Us
  • Company Overview

Trojan.Tibs.E

( TR/Tibs.E, Troj/DwnLdr-CBY, Trj/Gagar.I, TROJ_GALAPOPER.A, Downloader-ZQ )
Spreading: very low
Damage: very low
Size: ~6 Kb (packed)
Discovered: 2006 Jun 07

SYMPTOMS:

  • Unrecognized processes running in the background and requesting internet access (observable if a personal firewall is installed). Some processes that can be found on an infected machine are: ipor.raw.exe, taskdir~.exe (these are just examples and can change because the trojan contains an update feature)
  • Presence of the files svcp.csv and / or winsub.xml in the system directory

TECHNICAL DESCRIPTION:

This is a downloader trojan. Upon startup it checks if it's already running using a mutex named "gagagaradio". If it's already running, it exists. Otherwise it contacts downloads an encrypted file from http://81.177.[[removed]]/cntrl.php?[[removed]]. This encrypted file contains the links to other files which will be downloaded and executet. Currently this trojan downloads two files identified as Trojan.Agent.ON and Trojan.Proxy.Lager.BI, however this can change if the configuration on the remote server is changed. The trojan attempts to contact the computer with IP address 208.36.123.14 on port 25.

Removal instructions:

Please let BitDefender delete your files.

ANALYZED BY:

Attila Balazs, virus researcher

© 2010 BitDefender

  • Site Map
  • Legal Terms
  • Site Feedback
  • Global Sites
  • Privacy Policy

For Home Users

  • BitDefender® Total Security 2011
  • BitDefender® Internet Security 2011
  • BitDefender® Antivirus Pro 2011
  • BitDefender 2011 Product Comparison

For Small Business

  • For Small Business
  • BitDefender® Small Business Security for Desktops and File Servers
  • BitDefender® Small Business Security for Desktops, File Servers, and Exchange

News

  • BitDefender Finds IT Security Employees Likely to Disclose Sensitive Information on Social Networks
  • BitDefender Internet Security 2010 Receives Esteemed AV-Test Certification
  • BitDefender launches Total Security 2011 today to offer consumers a simplified and enhanced way to safeguard their online world

Tools & Resources

  • Free Online Virus Scanner
  • Renew Product Licence
  • Download Trial Versions
  • Download Datasheets