Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | July 2006 (4.07) |
| Protection available since | 2 May 2006 20:07:39 (GMT) |
| Last updated | 29 May 2006 22:16:27 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/FeebDl-M is a Trojan for the Windows platform.
The Trojan attempts to download and execute files from remote sites. The Trojan may arrive via email and may contain an attached file with the ZIP file extension. The ZIP file contains an HTML based script file which may have the file extension HTA.
Files are downloaded to C:\Recycled\userinit.exe
Troj/FeebDl-M creates the following registry entries:
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\(CD5AC91B-AE7B-E83A-0C4C-E616075972F3)\Stubpath
c:\Recycled\userinit.exe
HKCU\Software\Microsoft\Internet Explorer\mal
<email address>
The Trojan may delete the following registry entries, if they exist:
HKLM\SYSTEM\CurrentControlSet\Services
pcipim
HKLM\SYSTEM\CurrentControlSet\Services
pcIPPsC
HKLM\SYSTEM\CurrentControlSet\Services
RapDrv
HKLM\SYSTEM\CurrentControlSet\Services
FirePM
HKLM\SYSTEM\CurrentControlSet\Services
KmxFile
Troj/FeebDl-M may copy itself to the "Common Startup" folder as determined by the registry entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Common Startup
