Home Malware Programs Trojans Trojan.Febipos

Trojan.Febipos

Posted: May 14, 2013

Threat Metric

Ranking: 14,552
Threat Level: 8/10
Infected PCs: 14,359
First Seen: May 14, 2013
Last Seen: February 2, 2025
OS(es) Affected: Windows

Trojan.Febipos is a Trojan that compromises Facebook profiles on Google Chrome and Mozilla Firefox web browsers. Trojan.Febipos proliferates via harmful browser extensions in an effort to hijack Facebook profiles. When installed, Trojan.Febipos aims at updating itself using domain names like Google Chrome web browser - 'du-pont.info/updates//BL-chromebrasil.crx' and Mozilla Firefox web browser - 'du-pont.info/updates//BL-mozillabrasil.xpi'. Trojan.Febipos sees if an attacked PC user is logged in to Facebook at the time. Trojan.Febipos then aims at getting a configuration file from the website - .info/sqlvarbr.php. This configuration file comprises of a host of commands of what the browser extension will do. Depending on the file, Trojan.Febipos can do any of the certain actions in the Facebook profile of a corrupted PC such as like a page, share, post, join a group, invite friends to a group, chat to friends and comment on a post. The post adds that the configuration file was also found to involve a command to post bogus messages in Facebook.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Windows Service\service.exe File name: service.exe
Size: 119.2 KB (119208 bytes)
MD5: e6043572cb3bedc092482d6e5c6b88cf
Detection count: 6,237
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Windows Service
Group: Malware file
Last Updated: June 4, 2016
%LOCALAPPDATA%\NVIDIA Corporation\nvxsync.exe File name: nvxsync.exe
Size: 2.97 MB (2970638 bytes)
MD5: 10c3813691172c2a282d5382197600e8
Detection count: 860
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\NVIDIA Corporation
Group: Malware file
Last Updated: August 14, 2021
%LOCALAPPDATA%\ChromeUpdate\chromecheck.exe File name: chromecheck.exe
Size: 17.41 KB (17416 bytes)
MD5: e2f6d8375f61f270e508bb755bd0a439
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\ChromeUpdate
Group: Malware file
Last Updated: March 19, 2016

More files

Additional Information

The following messages's were detected:
# Message
1GAROTA DE 15 ANOS Và TIMA DE BULLYING COMETE SUICà DIO APÓS MOSTRAR OS SEIOS NO FACEBOOK
Vìdeo no link abaixo:<Currently unavailable link>
Translation from Portuguese into English:
15 YEAR-OLD VICTIM OF BULLYING COMMITS SUICIDE AFTER SHOWING HER BREASTS ON FACEBOOK.
Video on the link below: <Currently unavailable link>

Loading...