Also detected as:
The following could indicate that you have this threat on your PC:
Windows Defender detects and removes this threat.
This trojan can download and install other programs without your consent, including other malware.
See the Dofoil family description for more information.
Use the following free Microsoft software to detect and remove this threat:
You should also run a full scan. A full scan might find other hidden malware.
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.
If you’re using Windows XP, see our Windows XP end of support page.
When it runs, TrojanDownloader:Win32/Dofoil.R copies itself to %APPDATA%\feeba1.exe.
The malware modifies the following registry entries to ensure that it runs each time you start your computer:
In subkey: HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\RunSets value: "FlySky"With data: "%APPDATA%\feeba1.exe"
Contacts remote host
TrojanDownloader:Win32/Dofoil.R might contact a remote host at havecriticism.info using port 80. Commonly, malware contacts remote hosts for the following purposes:
This malware description was produced and published using our automated analysis system's examination of file SHA1 b61c093d45dbbbfa866195018f68fa2ffe572c9c.
Take these steps to help prevent infection on your PC.
I want to...
Note: Your feedback is very important to us, however we do not respond to individual submissions through this channel.
If you require support, please visit the
Safety & Security Center.