Home Malware Programs Backdoors Backdoor.Win32.Bifrose.for

Backdoor.Win32.Bifrose.for

Posted: January 11, 2011

Backdoor.Win32.Bifrose.for is a malicious backdoor Trojan which is able to run in the background making it very difficult to manually detect or remove. Trojan parasites such as Backdoor.Win32.Bifrose.for could put stored data on the infected PC at risk of being stolen. Backdoor.Win32.Bifrose.for can allow a remote attacker to connect to the system and download personal information stored on the hard drive of the infected computer. This is why we have to strongly suggest that Backdoor.Win32.Bifrose.for be detected and removed with a spyware removal program that is specifically designed to seek out Trojan parasites and other types of malware.

Aliases

BKDR_BIFROSE.DZZ (Trend Micro)
Mal/Bifrose-W, Mal/Behav-346, Mal/Inject-P (Sophos)
Virus.Win32.Inject (Ikarus)
Win-Trojan/Agent.11776.KS (AhnLab)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\Bifrost\logg.dat
    2 %System%\Bifrost\server.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C0E963F-CC76-7AA0-DF3C-53A15FC4D315}]HKEY..\..\..\..{RegistryKeys}klg = 01nck = ED 1B E6 27 B9 28 D6 32 74 C3 CD 74 FA 93 5B 67stubpath = "%System%\Bifrost\server.exe s"
Loading...