Sophos

Troj/FeebDl-M

Aliases
  • Worm.Win32.Feebs.gi
  • JS/Feebs.gen.a@MM
  • virus
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from July 2006 (4.07)
Protection available since 2 May 2006 20:07:39 (GMT)
Last updated 29 May 2006 22:16:27 (GMT)
Detected by All Sophos products

Action

More Information

Troj/FeebDl-M is a Trojan for the Windows platform.

The Trojan attempts to download and execute files from remote sites. The Trojan may arrive via email and may contain an attached file with the ZIP file extension. The ZIP file contains an HTML based script file which may have the file extension HTA.

Files are downloaded to C:\Recycled\userinit.exe

Troj/FeebDl-M creates the following registry entries:

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\(CD5AC91B-AE7B-E83A-0C4C-E616075972F3)\Stubpath
c:\Recycled\userinit.exe

HKCU\Software\Microsoft\Internet Explorer\mal
<email address>

The Trojan may delete the following registry entries, if they exist:

HKLM\SYSTEM\CurrentControlSet\Services
pcipim

HKLM\SYSTEM\CurrentControlSet\Services
pcIPPsC

HKLM\SYSTEM\CurrentControlSet\Services
RapDrv

HKLM\SYSTEM\CurrentControlSet\Services
FirePM

HKLM\SYSTEM\CurrentControlSet\Services
KmxFile

Troj/FeebDl-M may copy itself to the "Common Startup" folder as determined by the registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Common Startup

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer