Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | July 2006 (4.07) |
| Protection available since | 28 April 2006 20:53:14 (GMT) |
| Last updated | 26 May 2006 09:41:30 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/FeebDl-L is a Trojan for the Windows platform.
The Trojan attempts to download and execute files from remote sites. The Trojan may arrive via email and may contain an attached file with the ZIP file extension. The ZIP file contains an HTML based script file which may have the file extension HTA.
Downloaded files are placed in the C:\Recycled folder and are named "userinit.exe"
The Trojan may delete the following registry entries, if they exist:
HKLM\SYSTEM\CurrentControlSet\Services
pcipim
HKLM\SYSTEM\CurrentControlSet\Services
pcIPPsC
HKLM\SYSTEM\CurrentControlSet\Services
RapDrv
HKLM\SYSTEM\CurrentControlSet\Services
FirePM
HKLM\SYSTEM\CurrentControlSet\Services
KmxFile
Troj/FeebDl-L may copy itself to the "Common Startup" folder as determined by the registry entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Common Startup
