Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

TROJANDROPPER.AGENT.FYM

 

 

 

Name:

TrojanDropper.Agent.fym

Added:

October 19, 2011

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Description:

 

When TrojanDropper.Agent.fym is executed, it performs the following activities:

After execution, it drops the following files:

%Windir%\System32\mfc42ul.dll
%Windir%\System32\winsys32.sys
%Temp%\~acrd~tmp~.exe

It modifies/creates the following registry entries

ImagePath: "\??\%Windir%\winsys32.sys"
HKLM\SYSTEM\ControlSet001\Services\winsys32

This Trojan, once injected into Skype, monitors communications, captures screen shots and may download and execute files.

It infects the following set of processes.

explorer.exe
Skype.exe
SkypePM.exe
msnmsgr.exe
yahoomessenger.exe
x-lite.exe
sipgatexlite.exe
 
 

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Malware problems?
We can help.

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Evaluate Thirtyseven4 Antivirus Now

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4