Home Malware Programs Backdoors Backdoor.Bifrose.AHY

Backdoor.Bifrose.AHY

Posted: January 11, 2010

Backdoor.Bifrose.AHY is a malicious banking Trojan that disables firewalls and steals sensitive information such as credit card numbers and banking details. Backdoor.Bifrose.AHY records screen snapshots, downloads additional components, and gives an attacker the remote access to the corrupted computer system. Backdoor.Bifrose.AHY has stealth-mode features common to Rootkits that allow it to go undetected. Use an effective anti-spyware kit to detect and remove Backdoor.Bifrose.AHY from the infected system.

Aliases

Mal/EncPk-CI (Sophos)
Backdoor:Win32/Poison.M (Microsoft)
Win-Trojan/Poison.8192.I (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\addon.dat
    2 %ProgramFiles%\pic\picture.jpg

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\%UserName%914\-72398023][HKEY_CURRENT_USER\Software\%UserName%914]
Loading...