TROJANDROPPER.AGENT.FYM
Name:
TrojanDropper.Agent.fym
Added:
October 19, 2011
Type:
Trojan
Risk:
Low
Payload:
N/A
At risk systems:
Windows 95/98/ME/XP/NT/2003
Description:
When TrojanDropper.Agent.fym is executed, it performs the following activities:After execution, it drops the following files:%Windir%\System32\mfc42ul.dll%Windir%\System32\winsys32.sys%Temp%\~acrd~tmp~.exeIt modifies/creates the following registry entriesImagePath: "\??\%Windir%\winsys32.sys"HKLM\SYSTEM\ControlSet001\Services\winsys32This Trojan, once injected into Skype, monitors communications, captures screen shots and may download and execute files.It infects the following set of processes.explorer.exeSkype.exeSkypePM.exemsnmsgr.exeyahoomessenger.exex-lite.exesipgatexlite.exe
Malware problems?We can help.
Evaluate Thirtyseven4 Antivirus Now
“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4