Sophos

Troj/FeebDl-A

Aliases
  • Worm.Win32.Feebs.h
  • JS/Kmax.gen@MM
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from March 2006 (4.03)
Protection available since 11 January 2006 21:27:23 (GMT)
Last updated 25 January 2006 13:58:13 (GMT)
Detected by All Sophos products

Action

More Information

Troj/FeebDl-A is a downloader Trojan for the Windows platform.

Troj/FeebDl-A attempts to download one of several encoded executable files and decode it to C:/recycled/userinit.exe.

Troj/FeebDl-A attempts to delete the following registry entries:

HKLM\SYSTEM\CurrentControlSet\Services\KmxFile
HKLM\SYSTEM\CurrentControlSet\Services\pcipim
HKLM\SYSTEM\CurrentControlSet\Services\pcIPPsC
HKLM\SYSTEM\CurrentControlSet\Services\RapDrv
HKLM\SYSTEM\CurrentControlSet\Services\FirePM

Troj/FeebDl-A attempts to set the following registry entry in order to automatically start the file it has downloaded on system start:

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\
{CD5AC91B-AE7B-E83A-0C4C-E616075972F3}
Stubpath
C:/recycled/userinit.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer