Home Malware Programs Backdoors Backdoor.Win32.Poison.ajag

Backdoor.Win32.Poison.ajag

Posted: March 3, 2011

The Trojan Backdoor.Win32.Poison.ajag is reported to spread through email spam and compromises the security of any computer it comes into contact with in multiple ways. Backdoor.Win32.Poison.ajag will hide as a background process while initiating unauthorized downloads and collecting personal information from the system, attacking your privacy simultaneously along with your computer's stability. Removing Backdoor.Win32.Poison.ajag is central to keeping your computer's privacy and safety boundaries intact, but is best handled by anti-virus programs designed to delete such PC threats.

Backdoor.Win32.Poison.ajag ? the Virtual Hate Mail

Trojans like Backdoor.Win32.Poison.ajag are able to infect new systems in many ways, but almost always do so deceptively. Backdoor.Win32.Poison.ajag's apparent preferred method is through attachments in email messages it spams from infected computers to available contacts. If you don't care to get the Backdoor.Win32.Poison.ajag infection, try avoiding suspicious email attachments, even if they're from friends!

An installed Backdoor.Win32.Poison.ajag infection will make changes to your registry to allow it to run in the background right next to Windows. If you have access to Task Manager, you may be able to see Backdoor.Win32.Poison.ajag's process running in memory, but other than that you can expect little evidence of its existence.

Some other names Backdoor.Win32.Poison.ajag is detected under include Infostealer, Generic BackDoor!cjm, VirTool:Win32/VBInject.gen!AN and Mal/Behav-359.

After Opening the Envelope

A system that plays unwilling host to Backdoor.Win32.Poison.ajag will undergo problems related to both Trojans and spyware:

  • Backdoor.Win32.Poison.ajag will download files and execute them without requiring your permission. Extra files are invariably some form of malware, and may cause very visible problems or equally serious system damage that isn't easily seen at all.
  • Backdoor.Win32.Poison.ajag will give your computer over to remote attackers. This allows remote criminals to steal information or passively spy on your computer, and can even be taken to the extent of taking over the system or outright destroying it.
  • Backdoor.Win32.Poison.ajag is also widely reported to have keylogger functionality, which lets it capture each keystroke typed on your keyboard. Through keylogging, Backdoor.Win32.Poison.ajag can grab your passwords, account logins, credit card numbers and any other sensitive information that you happen to type.

Even if it were just a Trojan, Backdoor.Win32.Poison.ajag would be bad enough to earn hasty expelling from your computer. This Trojan's combination of Trojan and keylogger abilities just adds insult to injury and make deleting Backdoor.Win32.Poison.ajag an absolute imperative.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\addon.dat
    2 %AppData%\Microsoft\Crypto\RSA\S-1-5-21-606747145-764733703-839522115-1003\699c4b9cdebca7aaea5193cae8a50098_a7bcc1a4-f7a4-4502-8650-8579e607f7f7
    3 %PROGRAM_FILES%\Backdoor.Win32.Poison.ajag
    4 %System%\Bifrost\klog.dat
    5 %System%\Bifrost\server.exe
    6 c:\Documents and Settings\All Users\Backdoor.Win32.Poison.ajag \
    7 c:\Documents and Settings\All Users\Start Menu\Backdoor.Win32.Poison.ajag \

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\BifrostHKEY_LOCAL_MACHINE\SOFTWARE\BifrostHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}HKEY_LOCAL_MACHINE\Software\Backdoor.Win32.Poison.ajagHKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideostubpath = "%System%\Bifrost\server.exe s"
Loading...