Home Malware Programs Trojans Trojan.Win32.Jorik.Birfost.r

Trojan.Win32.Jorik.Birfost.r

Posted: August 29, 2011

Trojan.Win32.Jorik.Birfost.r is a damaging Trojan that attracts PC users by showing a window which poses as a MSN Messenger dialogue box and then asks them to type their MSN's account information into the box. If you add your password on the fake MSN Messenger dialogue box, a hacker can remotely gain acess to your MSN Messenger account. Trojan.Win32.Jorik.Birfost.r is advertised along with fake security programs to trick affected users into visiting the malicious websites and buying bogus programs that won't protect your PC from any type of viruses. Remove Trojan.Win32.Jorik.Birfost.r immediately after detection to safeguard your machine.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ProgramFiles%\Bifrost\server.exe File name: %ProgramFiles%\Bifrost\server.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideoHKEY_CURRENT_USER\Software\BifrostHKEY_LOCAL_MACHINE\SOFTWARE\BifrostHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo
Loading...