Sophos

Troj/Fanbot-G

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2008 (4.30)
Protection available since 23 April 2008 04:01:13 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Fanbot-G drops the following files which are also detected as Troj/Fanbot-G:
<Profile>\Local Settings\Temp\1.sys
<Profile>\Local Settings\Temp\2.sys

Troj/Fanbot-G registers itself as Netmanager Service and iCafe Service.

Troj/Fanbot-G contains functionality to stealth itself.

Troj/Fanbot-G creates the entries in "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options". Each entry is named after an application that that Troj/Fanbot-G disables. Deleting these entries will re-enable the application.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer