Home Malware Programs Trojans Finfanse

Finfanse

Posted: March 28, 2006

Finfanse is a trojan that attempts to steal confidential user information by capturing screenshots of many online PC games such as Final Fantasy and Front Mission Online. The spyware silently uploads gathered data to a predetermined FTP server. It also retrieves computer information and transfers it to a predefined web server. Finfanse automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 exploreff.exe
    2 systemlff.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunexploreff.exe
Loading...