Home Malware Programs Backdoors Backdoor.Linfo

Backdoor.Linfo

Posted: May 17, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 66
First Seen: May 17, 2012
Last Seen: June 12, 2022
OS(es) Affected: Windows

Backdoor.Linfo is a backdoor Trojan that opens a back door on the compromised PC system. Once executed, Backdoor.Linfo creates a few files. Backdoor.Linfo then creates the particular mutex 'ExplorerIsShellMutex' so that only one instance is running on the affected machine. Then, Backdoor.Linfo opens a back door by connecting to the specific locations [http://]www.ancold.org.au/mycfg/mycmd/[ENCODED HO[REMOVED] and [http://]www.ancold.org.au/mycfg/myscr/Myup[REMOVED]and awaits instructions from the remote attacker. The remote attacker can perform numerous malicious actions such as download, upload, execute, delete, move, and copy files, upload system information, list running processes and contents of local drive, start a remote shell, search for local files, and many other. You should eliminate Backdoor.Linfo as early as possible by using a genuine malware removal program.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\AppPatch\lsass.exe File name: lsass.exe
Size: 206.16 KB (206167 bytes)
MD5: cc97965b842a77fc4b2b45ec7eb630f9
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\AppPatch
Group: Malware file
Last Updated: March 13, 2020
C:\Program Files (x86)\msinfo64.exe File name: msinfo64.exe
Size: 809.98 KB (809984 bytes)
MD5: af5e9c258a7df4e5affae8e830af7704
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)
Group: Malware file
Last Updated: March 13, 2020
%Windir%\linkinfo.dll File name: %Windir%\linkinfo.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Windir%\tp.ds File name: %Windir%\tp.ds
Mime Type: unknown/ds
Group: Malware file
%Windir%\tp.dat File name: %Windir%\tp.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%ProgramFiles%\Internet Explorer\lg.dat File name: %ProgramFiles%\Internet Explorer\lg.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%PROGRAMFILES(x86)%\msinfo64.exe
Loading...