Home Malware Programs Trojans Trojan.Win32.Refroso.djjg

Trojan.Win32.Refroso.djjg

Posted: July 18, 2011

Trojan.Win32.Refroso.djjg is a Trojan that can display a wide range of hostile functions, depending on which variant of Trojan.Win32.Refroso.djjg is attacking your PC. However, despite its variability, Trojan.Win32.Refroso.djjg is always a serious security risk that should be deleted with the highest-quality security software that's available. Some common Trojan.Win32.Refroso.djjg attacks include disabling Safe Mode, launching itself without permission, modifying system settings to harm your computer's security, concealing memory processes and hijacking your web browser. However, any given Trojan.Win32.Refroso.djjg infection may also show other symptoms or no symptoms at all.

A Brief Summary of Trojan.Win32.Refroso.djjg's Not-So-Brief Hostilities Against Your Computer

Most reported Trojan.Win32.Refroso.djjg infections are quite new, and as of July 2011, Trojan.Win32.Refroso.djjg is still a poorly-documented Trojan, that may evade inadequate or non-updated security software. Keep your security software's threat definitions updated to even the odds against Trojan.Win32.Refroso.djjg's wild array of attacks.

Damage that's inflicted by Trojan.Win32.Refroso.djjg can take the following forms, but isn't restricted to this list:

  • Trojan.Win32.Refroso.djjg may create a backdoor in your security that lets remote attackers control your PC. Backdoors can sometimes be detected by noticing opened network ports, changed system settings or dysfunctional security application behavior. However, Trojan.Win32.Refroso.djjg may use the Windows Registry to make these attacks, which will minimize visible side effects.
  • Trojan.Win32.Refroso.djjg may also launch hidden memory processes; this allows Trojan.Win32.Refroso.djjg to engage in many different kinds of harmful behavior without being seen in Task Manager. One example is iexplore.exe, which Trojan.Win32.Refroso.djjg has been seen launching and hiding to use Internet Explorer for various misdeeds.
  • Some variants of Trojan.Win32.Refroso.djjg may also install other harmful programs (known as the Trojan's 'payload'). Standard Trojan payloads include fake security software, spyware, worms and browser hijackers, among other possibilities.
  • Even the information that's saved on your PC might not be safe from Trojan.Win32.Refroso.djjg, which has been reported to enable spyware behavior in some cases. Trojan.Win32.Refroso.djjg may take screenshots of your screen, use keylogging functions to record typed information or scan your files for passwords and other private information.

The Trouble with Pinning Down Trojan.Win32.Refroso.djjg

Since Trojan.Win32.Refroso.djjg is used for wildly different types of backdoor Trojans, dropper Trojans, viruses and even worms, identifying a Trojan.Win32.Refroso.djjg infection may be difficult without the use of an anti-virus application. Although all Trojan.Win32.Refroso.djjg variants so far share the trait of changing your Windows Registry, some variants will make minor changes such as adding self startup entries while others may delete whole swathes of Windows settings.

Using Safe Mode or booting your computer from an alternate source (such as a Windows CD) is strongly recommended. Once you've done this, Trojan.Win32.Refroso.djjg will fail to launch, and you'll be able to delete Trojan.Win32.Refroso.djjg by applying any good anti-virus program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 c:\Bifrost\server.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\BifrostHKEY_CURRENT_USER\Software\MicroNoftHKEY_CURRENT_USER\Software\MicroNoft\WindowsHKEY_CURRENT_USER\Software\MicroNoft\Windows\CurrentVersionHKEY_CURRENT_USER\Software\MicroNoft\Windows\CurrentVersion\Internet SettingsHKEY_LOCAL_MACHINE\SOFTWARE\BifrostHKEY_LOCAL_MACHINE\SOFTWARE\MicroNoftHKEY_LOCAL_MACHINE\SOFTWARE\MicroNoft\Active SetupHKEY_LOCAL_MACHINE\SOFTWARE\MicroNoft\Active Setup\Installed ComponentsHKEY_LOCAL_MACHINE\SOFTWARE\MicroNoft\Active Setup\Installed Components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}HKEY_LOCAL_MACHINE\SOFTWARE\MicroNoft\WindowsHKEY_LOCAL_MACHINE\SOFTWARE\MicroNoft\Windows\CurrentVersionHKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
Loading...