Threat description



The Feliz trojan appeared on the 1st of January 2000. This trojan is written in Delphi. Being run the trojan first outputs a dialog with a picture and a single button:

When the button is clicked the trojan looks for C:\Windows\ directory and if it is found outputs the final messagebox:

At the same time the trojan deletes the following files:


Then the trojan passes control to the operating system. At this time the operating system becomes unstable and it will no longer start after next computer reboot.

If C:\Windows\ directory is not found by the trojan it will output a number of messageboxes and pass control to operating system without activating its payload.


Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Submit a Sample

Suspect a file or URL was wrongly detected? Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info