Home Malware Programs Worms Feebs.b

Feebs.b

Posted: March 28, 2006

Feebs.b is a rapidly spreading Internet worm, which propagates by e-mail in messages with malicious attachments and through file sharing networks using popular peer-to-peeer softwares. The user can accidentally infect a PC by opening an infected e-mail attachment or download the spyware as a purportedly useful application.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 command.exe
    2 ms[X1].exe
    3 ms[X2]32.dll
    4 ms[X3]

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerweb=[siteaddress]HKEY_CURRENT_USERSoftwarePoliciesMicrosoftWindowsFirewallDomainProfileEnableFirewall=0HKEY_CURRENT_USERSoftwarePoliciesMicrosoftWindowsFirewallStandardProfileEnableFirewall=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftMS[X4]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad[filename]HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallDomainProfileEnableFirewall=0HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallStandardProfileEnableFirewall=0
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}CD5AC91B-AE7B-E83A-0C4C-E616075972F3
Loading...