Troj/BHO-FY is a Trojan for the Windows platform.

Troj/BHO-FY has the functionalities to:

  • download a file from preconfigured URL to (windows)/(9 random characters)
  • read data from (windows)\(9 random characters)
  • delete (windows)\(9 random characters)

    The following registry entry is created:
    HKCU\Software\Microsoft\ppp\c
    tm
    180

    HKCU\Software\Microsoft\ppp\c
    u
    preconfigured URL

    HKCU\Software\Microsoft\ppp\c
    k
    url,field2,homepage,hp,internet,website,reg_home_page

    More information can be found at this Sophos page.