Home Malware Programs Backdoors Backdoor.Win32.Bifrose.ahfs

Backdoor.Win32.Bifrose.ahfs

Posted: February 15, 2011

Backdoor.Win32.Bifrose.ahfs is a backdoor Trojan that attacks the firewall and other security aspects of a PC while running as a hidden background process. In some cases Backdoor.Win32.Bifrose.ahfs may drop other malware such as keyloggers or rogue security products onto the affected computer. An infection of Backdoor.Win32.Bifrose.ahfs is a serious threat to your privacy and safety, since Backdoor.Win32.Bifrose.ahfs allows remote attackers to take over the computer and use it for their own purposes. Removing Backdoor.Win32.Bifrose.ahfs is most reliable when done by a trained expert or by proven anti-malware applications that have been updated to identify this Trojan threat.

Backdoor.Win32.Bifrose.ahfs is a Malware Problem that Causes Even More Problems

PCs infected by Backdoor.Win32.Bifrose.ahfs may not behave differently in a visible manner. During the initial infection routine, Backdoor.Win32.Bifrose.ahfs will often be compressed to avoid triggering anti-malware program alerts. When installing, Backdoor.Win32.Bifrose.ahfs will also make Registry additions that let Backdoor.Win32.Bifrose.ahfs run without detection in the background.

Backdoor.Win32.Bifrose.ahfs is often bundled with other infections, including other types of Trojans and keyloggers that steal passwords and general keyboard input. Since Backdoor.Win32.Bifrose.ahfs gives indications of being from Russia, it may be wise to keep up particularly strict security measures when downloading files from a user in that region.

Actual Attacks by Backdoor.Win32.Bifrose.ahfs Consist of the Following, at a Minimum:

  • Reduced security settings. Your firewall and other security measures may be temporarily or permanently disabled by Backdoor.Win32.Bifrose.ahfs to allow Backdoor.Win32.Bifrose.ahfs to access external servers and potential remote hackers. In some cases, this can include blocking security-related applications from running at all.
  • Easy access by anonymous and remote criminals. Most Trojans like Backdoor.Win32.Bifrose.ahfs will notify the criminal when they manage to infect a fresh computer, making further attacks simple on the part of the criminal. These remote attackers may take advantage of your PC's situation to steal passwords, install secretive spyware or force your computer into being part of a botnet.
  • The unauthorized download and installation of other malicious software. This is a secondary but still significant purpose for this backdoor Trojan; Backdoor.Win32.Bifrose.ahfs can install programs without requiring any interaction or awareness from the user. Common types of malicious software can try to present themselves off as real applications; you should be concerned if you see a new program installed on your computer without your explicit consent and approval

Why You Shouldn't Wait to Give Backdoor.Win32.Bifrose.ahfs a Farew

Not deleting Backdoor.Win32.Bifrose.ahfs or other backdoor Trojans when you're able to do so will almost always result in highly negative consequences for your PC and any information contained therein. Remote attackers can use your PC for whatever purposes suit them, and may cause permanent damage or steal financial or identity-based data. Other malware downloads can make it hard or even impossible to remove the infections if allowed to accumulate.

Using a widely-known and trusted anti-malware program to remove Backdoor.Win32.Bifrose.ahfs is usually better than opting for manual removal. Trojans like Backdoor.Win32.Bifrose.ahfs will often use techniques to avoid direct deletion, but any good anti-malware scanner with complete updates can clean this Trojan out with no problems.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Company\sex\Bind.exe
    2 %ProgramFiles\Company\sex\Uninstall.exe
    3 %ProgramFiles\Company\sex\Uninstall.ini
    4 %System \mms\msn.exe
    5 %Temp \ljnxbbugjb.flv
    6 %Temp%\gmytpvuyws.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\BifrostHKEY_CURRENT_USER\Software\MicrosoHKEY_LOCAL_MACHINE\SOFTWARE\BifrostHKEY_LOCAL_MACHINE\SOFTWARE\MicrosoHKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}sex 1.00
Loading...