Sophos

Troj/Feebs-CA

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
  • Monitors browser activity
Protection available since 2 January 2008 23:42:41 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

Troj/Feebs-CA is a Trojan for the Windows platform.

Troj/Feebs-CA includes functionality to stealth itself.

Troj/Feebs-CA creates the following files:
<System>\ms<two random letters>32.dll
<System>\ms<two random letters>.exe

Troj/Feebs-CA creates the following registry entries:
HKLM\Software\Microsoft\MSAM
HKCR\CLSID\<random class id>
HKLM\Software\Microsoft\Active Setup\Installed Components\<random class id>

These registry entries are created in HKCU if HKLM is not writable.

Troj/Feebs-CA payload performs the following malicious tasks:
- scans the network connection for user ids and passwords
- retrieves contacts from address books
- downloads and executes other malicious files
- sends out spam
- uploads files from the local hard drive to a remote server
- records keystrokes
- captures contents of windows for financial and shopping web sites

Troj/Feebs-CA also interferes with virus scanning and firewall software.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer