Home Malware Programs Worms Feebs.j

Feebs.j

Posted: March 28, 2006

Feebs.j is a rapidly spreading Internet worm, which propagates by e-mail in messages with malicious attachments and through file sharing networks using popular peer-to-peer softwares. The user can accidentally infect a PC by opening an infected e-mail attachment or download the spyware as a puportedly useful application.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 ms[X1].exe
    2 ms[X2]32.dll
    3 ms[X3]
    4 userinit.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftInternetExplorermalHKEY_CURRENT_USERSoftwareMicrosoftInternetExplorerwebHKEY_CURRENT_USERSoftwarePoliciesMicrosoftWindowsFirewallDomainProfileEnableFirewall=0HKEY_CURRENT_USERSoftwarePoliciesMicrosoftWindowsFirewallStandardProfileEnableFirewall=0HKEY_LOCAL_MACHINESOFTWAREMicrosoftMS[X4]HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoad[filename]HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallDomainProfileEnableFirewall=0HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsFirewallStandardProfileEnableFirewall=0
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}CD5AC91B-AE7B-E83A-0C4C-E616075972F3
Loading...