Threat Database Backdoors Backdoor.Finfish

Backdoor.Finfish

By Domesticus in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 9
First Seen: July 27, 2012
Last Seen: December 13, 2018
OS(es) Affected: Windows

Backdoor.Finfish is a Trojan that opens a back door on the affected PC. When activated, Backdoor.Finfish may create many harmful files. Backdoor.Finfish also creates a few registry entries. Backdoor.Finfish allows attcakers to obtain remote access and control over the targeted machine. Backdoor.Finfish may then contact the specific command-and-control (C&C) servers. Backdoor.Finfish may then transfer stolen information to remote servers.

SpyHunter Detects & Remove Backdoor.Finfish

File System Details

Backdoor.Finfish may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\shellex32.dll
2. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\mssounddx.sys
3. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\04C.dat
4. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\05.dat
5. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\7FC.dat
6. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\10.dat
7. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\12C.dat
8. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\14.dat
9. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\17C.dat
10. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\18.dat
11. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\21C.dat
12. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\80C.dat
13. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\04.dat
14. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\02C.dat
15. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\7F.dat
16. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\11C.dat
17. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\12.dat
18. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\16C.dat
19. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\17.dat
20. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\19C.dat
21. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\21.dat
22. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\20C.dat
23. %Temp%\tmp2.tmp
24. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\02.dat
25. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\05C.dat
26. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\11.dat
27. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\10C.dat
28. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\16.dat
29. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\14C.dat
30. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\19.dat
31. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\18C.dat
32. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\20.dat
33. %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\ico_ty23.ico

Registry Details

Backdoor.Finfish may create the following registry entry or registry entries:
Regexp file mask
%ALLUSERSPROFILE%\HelperService\d3d9.dll
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSSOUNDDX
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssounddx

Directories

Backdoor.Finfish may create the following directory or directories:

%ALLUSERSPROFILE%\NdisSrv

Trending

Most Viewed

Loading...