Backdoor

Backdoor.Finfish removal instruction

Malware Removal

The Backdoor.Finfish is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Finfish virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Backdoor.Finfish?


File Info:

crc32: 8F2B9E11
md5: 1d4fc4fafd89fecda1fb54e68a09283b
name: 1D4FC4FAFD89FECDA1FB54E68A09283B.mlw
sha1: 746b12ead3abad163addc6223b927537a5814ced
sha256: e9f75c098639796f29d8b2c029a02fd26a183fcbaf4701e66892d4256f88817f
sha512: dc42b99e83946d5623323cdc010c0ac5d7f5d34107801612d6d3afd28b188c2a5191137eef9efdc2dd3e3d45486891a262081bd3c547de97472ef914532b7c83
ssdeep: 49152:Qoa1taC070dhJ5FWGzd4pa6xNaMLSPfAC:Qoa1taC0WJrWGpoxNavPfR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Finfish also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44375344
FireEyeGeneric.mg.1d4fc4fafd89fecd
ALYacTrojan.GenericKD.44375344
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 004fdf0a1 )
BitDefenderTrojan.GenericKD.44375344
K7GWTrojan ( 004fdf0a1 )
Cybereasonmalicious.afd89f
CyrenW32/S-8e0acc48!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Finfish.ow
NANO-AntivirusTrojan.Win32.Salgorea.ellsnj
TencentMalware.Win32.Gencirc.10b2f8c3
Ad-AwareTrojan.GenericKD.44375344
SophosML/PE-A + Mal/Salgorea-A
ComodoTrojWare.Win32.Salgorea.AQ@73zvwa
F-SecureHeuristic.HEUR/AGEN.1117294
DrWebTrojan.MulDrop7.43397
ZillyaTrojan.Black.Win32.47443
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftTrojan.GenericKD.44375344 (B)
IkarusTrojan.Win32.Skeeyah
JiangminBackdoor.Finfish.y
AviraHEUR/AGEN.1117294
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Generic.D2A51D30
ZoneAlarmBackdoor.Win32.Finfish.ow
GDataTrojan.GenericKD.44375344
TACHYONBackdoor/W32.Finfish.1958400
AhnLab-V3Malware/Win32.Generic.C1664134
Acronissuspicious
McAfeeGenericRXAO-HZ!1D4FC4FAFD89
MAXmalware (ai score=80)
VBA32Backdoor.Finfish
MalwarebytesAutoKMS.HackTool.Patcher.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Salgorea.AQ
RisingBackdoor.Finfish!8.192 (TFE:5:xsaFnaNFiqD)
YandexTrojan.GenAsa!Vl/tO0Uk9tE
SentinelOneStatic AI – Malicious PE – Downloader
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AC.39E2FE!tr
BitDefenderThetaAI:Packer.DFB6820820
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM20.1.057B.Malware.Gen

How to remove Backdoor.Finfish?

Backdoor.Finfish removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment