Home Malware Programs Backdoors Backdoor.Finfish

Backdoor.Finfish

Posted: July 27, 2012

Threat Metric

Threat Level: 6/10
Infected PCs: 21
First Seen: July 27, 2012
Last Seen: December 13, 2018
OS(es) Affected: Windows

Backdoor.Finfish is a backdoor Trojan that opens a back door on the infected computer. Once executed, Backdoor.Finfish may create numerous malicious files. Backdoor.Finfish also creates several registry entries. Backdoor.Finfish may then connect to the particular command-and-control (C&C) servers. Backdoor.Finfish may then transmit stolen information to remote locations.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%\tmp2.tmp File name: %Temp%\tmp2.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\04.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\04.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\04C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\04C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\02.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\02.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\02C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\02C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\05.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\05.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\05C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\05C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\7F.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\7F.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\7FC.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\7FC.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\11.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\11.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\11C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\11C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\10.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\10.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\10C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\10C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\12.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\12.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\12C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\12C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\16.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\16.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\16C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\16C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\14.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\14.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\14C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\14C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\17.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\17.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\17C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\17C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\19.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\19.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\19C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\19C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\18.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\18.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\18C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\18C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\21.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\21.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\21C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\21C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\20.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\20.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\20C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\20C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\mssounddx.sys File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\mssounddx.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\shellex32.dll File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\shellex32.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\80C.dat File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\80C.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\ico_ty23.ico File name: %UserProfile%\Application Data\Microsoft\Installer\[RANDOM CLSID]\ico_ty23.ico
Mime Type: unknown/ico
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\HelperService\d3d9.dllHKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mssounddxHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSSOUNDDX

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\NdisSrv
Loading...