Sophos

Troj/FeebDl-L

Aliases
  • Worm.Win32.Feebs.gen
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
Included in our products from July 2006 (4.07)
Protection available since 28 April 2006 20:53:14 (GMT)
Last updated 26 May 2006 09:41:30 (GMT)
Detected by All Sophos products

Action

More Information

Troj/FeebDl-L is a Trojan for the Windows platform.

The Trojan attempts to download and execute files from remote sites. The Trojan may arrive via email and may contain an attached file with the ZIP file extension. The ZIP file contains an HTML based script file which may have the file extension HTA.

Downloaded files are placed in the C:\Recycled folder and are named "userinit.exe"

The Trojan may delete the following registry entries, if they exist:

HKLM\SYSTEM\CurrentControlSet\Services
pcipim

HKLM\SYSTEM\CurrentControlSet\Services
pcIPPsC

HKLM\SYSTEM\CurrentControlSet\Services
RapDrv

HKLM\SYSTEM\CurrentControlSet\Services
FirePM

HKLM\SYSTEM\CurrentControlSet\Services
KmxFile

Troj/FeebDl-L may copy itself to the "Common Startup" folder as determined by the registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Common Startup

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer