Home Malware Programs Trojans TROJ_FYNLOSKI.BU

TROJ_FYNLOSKI.BU

Posted: May 7, 2013

Threat Metric

Ranking: 9,560
Threat Level: 9/10
Infected PCs: 389
First Seen: May 7, 2013
Last Seen: February 9, 2025
OS(es) Affected: Windows

TROJ_FYNLOSKI.BU is a Trojan that spreads via AutoIt, a very flexible coding language in Windows, via hacked websites like Pastebin and Pastie. The websites contain a malicious AutoIt tool code, which is used by attackers to infect computers with TROJ_FYNLOSKI.BU. TROJ_FYNLOSKI.BU is a variant of the popular DarkComet RAT written utilizing AutoIt. TROJ_FYNLOSKI.BU runs a backdoor on the victimized PC and communicates outbound to a corrupt host. TROJ_FYNLOSKI.BU also modifies the local software firewall policies to disable them, in addition to installing itself at startup for persistency. TROJ_FYNLOSKI.BU also drops the potentially malicious file after execution. Upon execution, TROJ_FYNLOSKI.BU immediately disables the Windows Firewall. After disabling the firewall, TROJ_FYNLOSKI.BU then disables the ability to get into the registry of Windows to view or undo the modifications performed. In an attempt to do so, TROJ_FYNLOSKI.BU displays the error message.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



tb2323xt.exe File name: tb2323xt.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Additional Information

The following messages's were detected:
# Message
1Registry editing has been disabled by your administrator.

Loading...