Home Malware Programs Backdoors Backdoor.Win32.Bifrose.ahyw

Backdoor.Win32.Bifrose.ahyw

Posted: June 6, 2011

Backdoor.Win32.Bifrose.ahyw is a malicious computer backdoor trojan which is created by hackers to remotely access to the compromised computer. Backdoor.Win32.Bifrose.ahyw does not use network resources to spread, but can spread through a network by attaching itself to other computer malware threats. Backdoor.Win32.Bifrose.ahyw may collect your personal information, change or delete system files and result in general system instability on your computer. Backdoor.Win32.Bifrose.ahyw uses advanced rootkit techniques to hide any files and registry entries it creates. Remove Backdoor.Win32.Bifrose.ahyw as quickly as possible to protect your computer.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\dllcache\termsrvhack.dll
    2 %System%\termsrvhack.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RDPWDHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RDPWD\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RDPWD\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDTCPHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDTCP\0000HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDTCP\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RDPWDHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RDPWD\0000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RDPWD\0000\ControlHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDTCPHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDTCP\0000HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDTCP\0000\Control
Loading...