Title: Feebs.j
Type: Worms

Remove Feebs.j. Removal instructions


 
Severity scale:Feebs.j severity is 71  (71 / 100)
 
Feebs.j is a rapidly spreading Internet worm, which propagates by e-mail in messages with malicious attachments and through file sharing networks using popular peer-to-peer applications. The user can accidentally infect a computer by opening an infected e-mail attachment or download the parasite as a puportedly useful program.

Once executed, Feebs.j silently installs itself to the system and runs a spreading routine. The worm sends malicious letters to all the addresses it finds on the compromised computer. It also creates infected files with meaningful names in shared folders of installed peer-to-peer programs.

The parasite's payload is comprised of several harmful functions. Feebs.j collects user sensitive information including various passwords, account details and e-mail addresses, and transfers it to the attacker. The worm terminates running antiviruses, firewalls and other security-related programs and prevents them from running on system startup. It also cripples and disables most system services and shuts down the Windows Firewall. Furthermore, Feebs.j may run a hidden web server used to spread the infection. The parasite uses an integrated rootkit component, which injects malicious code into all active processes in order to hide the worm's files and registry entries.

Feebs.j automatically runs on every Windows startup.

Feebs.j properties:
• Sends out logs by FTP or email
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Feebs.j removal:

SpyHunter is recommended remover to uninstall Feebs.j. You should confirm using free trial that it detects current version of parasite.

Note: Manual assistance required means that one or all of removers were unable to remove parasite without some manual intervention, please read manul removal instructions below.

If you failed to remove Feebs.j using SpyHunter please report this to us.

We might be affiliated with any product we recommend on the site. Full disclosure in our Agreement of Use.
STOPzilla
We are testing STOPzilla's efficiency at removing Feebs.j (2006-01-17 11:50:57)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency at removing Feebs.j (2006-01-17 11:50:57)
Spyware Doctor
We are testing Spyware Doctor's efficiency at removing Feebs.j (2006-01-17 11:50:57)
XoftSpySE Anti Spyware

Feebs.j manual removal:

Kill processes:
ms[X1].exe, userinit.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\[filename]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CD5AC91B-AE7B-E83A-0C4C-E616075972F3}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\mal
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\web
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\EnableFirewall=0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS[X4]
Delete files:
ms[X1].exe, userinit.exe, ms[X2]32.dll, ms[X3]
Misc:
[X1], [X2], [X3] and [X4] are four different strings comprised of random characters.

Filenames may vary. Feebs.j creates randomly named registry keys.

Exact file location:
userinit.exe - C:\Recycled
ms[X1].exe, ms[X2]32.dll, ms[X3] - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
Information added: 2006-01-17 09:13:42
Information updated: 2006-01-17 09:13:42

Additional resources related to Feebs.j:

Attention: If you know or you have a website or page about Feebs.j removal, feel free to add a link to this list: add url

more resources

Post Comment:

Attention: Use this form only if you have additional information about Feebs.j parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Home page Name



«


* All field required
Latest spyware news:
Subscribe to news

Similar parasites:
Compare spyware removers
Compare free products

HijackThis Log Analyzer Beta 2 HijackThis Log Analyzer Beta 2

I failed to remove Feebs.j using SpyHunter.

Email


Close

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other