dialer.tibs help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by burnera, Sep 9, 2004.

  1. burnera

    burnera Private E-2

    its a dialer program that uses a modem to get to websites.
    keeps trying to connect to http;//install.xxxtool ....

    Norton Anti-virus detects it, but cant delete it in normal mode. Norton says i have to reboot in safe-mode and scan again.

    I have a sony vaio from this year, and cant seem to figure out how to reboot in safe mode. F8 just takes me to what drive i want to load from.

    this dialer seems to have survived multiple scans from Ad-Aware SE, and
    sygate firewall doesnt seem to stop it (though it maynot be connecting anywhere).

    also, i cant delete the file manually.

    it installs shortcuts onto the desktop going to:
    C:\Program Files\WebSiteViewer\121711.exe" /ac:121711 /sk: /lc: /ul

    the file 121711.exe cant be deleted manually.


    i'm running windows XP. have scanned with bazooka, adaware, cwsshredder , BHOdemon
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  3. PhilliePhan

    PhilliePhan Guest

    Last edited by a moderator: Sep 9, 2004
  4. burnera

    burnera Private E-2

    i might have got it. i stopped the system restore function and ran adware again, now the website search folder is empty.


    about safe mode: i dont know how! i can do it on any computer but mine, lol. F8 takes me to a list of my drives (cd, a, c, etc.) and asks which one i want to boot from, not what kind of boot.

    running XP on a sony vaio, sp1. i can think of what other specs would be related to a restart... are there options i can access in XP for safe mode?
    i thought i remembered seeing "restart in safe mode" somewhere in time.

    an aside: i still find win 98 more user freindly.


    edit: GAH!! its back .. same thing
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Hmmm, odds are your Sony is using f8 for the bios then.

    Go to start, run, msconfig and hit enter.
    Go to the boot.ini tab.
    Check safeboot and minimal since you dont need to scan online
    Apply. Reboot.

    Scan away. It might be gone, but they often come back without a safe mode scan.

    Go back to msconfig and uncheck safeboot before rebooting out of safe mode.
     
  6. burnera

    burnera Private E-2

    thanks major attitude, you were right about the safemode

    i got into safemode, scanned with ad-aware, cwshredder, about buster,
    CCLeaner. i also have system restore turned off.

    rebooted into normal mode, 10 min later without wandering the web (only went to google and here) cws search was back.

    rebooted in safe mode, ran norton anti-virus. it took 2 hours and it found 14 files and a virus. was only able to fix 2 of the files. the virus was
    bloodhound.

    that suckes, so i ran everyhing above again.

    rebooted into normal mode, all looked good.

    then i got it back, cws search and website viewer again.

    so i'm off to read your guides thoroughly, any suggestions in the mean time?
     
  7. MDren68

    MDren68 Private E-2

    I have been fighting something that I thought was TIBS also; but now I think it is something else. I suspect that "it" is reloading TIBS and XXXToolbar and 'Plugin' as well as other crap. I threw everything in my arsenal at it. I have used Norton Antivirus 9.0, adaware 1.04, spybot S&D 13, webroot SpySweeper, Bulletproof Spyware-Adware Remover, SpyhunterS, Spywareblaster, and Spykiller2005, and Spybouncer.

    I spent four hours in Safe Mode running all these. The last two or three did not find anything after the others had pretty much gotten rid of everything. Reboot and Voila! Reinfected!

    Pest Patrol's web site says that to get rid of TIBS you must delete your win.com file. You get rid of your ability to run Windows at that point as it is a legitimate file.

    Is there something else out there that hasn't been detected yet?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not using the proper version of Ad-Aware SE. You were supposed to check the links given to you in the READ ME FIRST tutorial. Always check for updates too. Note: all of the following are considered rogue/fake spyware removal tools:
    Bulletproof Spyware-Adware Remover, SpyhunterS, Spykiller2005, and Spybouncer.
    See this link: http://www.spywarewarrior.com/rogue_anti-spyware.htm
    You should uninstall them.

    You started out ths thread by saying you could not delete C:\Program Files\WebSiteViewer\121711.exe. Now you are saying you have a CWS problem. Is this file still a problem? And how do you know you have a CWS problem? Who is telling you this and what exactly does it say?

    You should read thiis: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    And then post a HijackThis log. Make sure you follow directions and post it as an attachment too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds