Home Malware Programs Trojans Infostealer.Fightpos

Infostealer.Fightpos

Posted: May 14, 2015

Threat Metric

Threat Level: 9/10
Infected PCs: 21
First Seen: May 14, 2015
OS(es) Affected: Windows

Infostealer.Fightpos is a detection name for a Backdoor Trojan that is currently affecting your computer. As the detection name suggests, the Infostealer.Fightpos was created for the purpose of stealing information. Trojans like Infostealer.Fightpos typically open a back door and collected the targeted info. Infostealer.Fightpos may steal information by exploiting security holes in the infected PC. Often, users may become victims of such infections when they visit malicious domains by accident or fall prey to a spam e-mail campaign. Consequently, computer security experts advise users not to open e-mails from unknown senders or ones with questionable attachments. In addition, it is recommended to keep a trusted anti-malware scanner always up to date and use it for detecting and removing infections such as Infostealer.Fightpos.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%\ActiveComponent.bat File name: %Temp%\ActiveComponent.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
%Temp%\ActiveComponent.exe File name: %Temp%\ActiveComponent.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\Application Data\Microsoft\InternetExplorer.exe File name: %UserProfile%\Application Data\Microsoft\InternetExplorer.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%UserProfile%\Start Menu\Programs\Startup\Shortcut to Internet Explorer.lnk File name: %UserProfile%\Start Menu\Programs\Startup\Shortcut to Internet Explorer.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"Microsoft" = "%UserProfile%\Application Data\Microsoft\InternetExplorer.exe"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"ActiveControl" = "%Temp%\ActiveComponent.bat"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"[PATH OF THE ORIGINAL FILE]" = "[PATH OF THE ORIGINAL FILE]:*:Enabled: Microsoft"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%UserProfile%\Application Data/Microsoft/InternetExplorer.exe" = "%UserProfile%\Application Data\Microsoft\InternetExpHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\"DoNotAllowExceptions" = "0"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA" = "0"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\"UACDisableNotify" = "0"

Additional Information

The following URL's were detected:
[http://]69.195.77.74/BrFighter/bot/comma[REMOVED]
Loading...