Home Malware Programs Trojans Suspicious.Bifrose

Suspicious.Bifrose

Posted: December 10, 2009

Suspicious.Bifrose, also known as New Malware.ab, is a malicious Trojan which stealthily enters the system and operates in the background. Suspicious.Bifrose is armed with a keylogger program which captures all the PC user's keystrokes and then sends them to malicious hackers. Suspicious.Bifrose may also contain an adware program designed to deliver annoying pop-ups and advertisements to infected system. Suspicious.Bifrose poses a severe threat to computer security and should be terminated when detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %FontsDir%\iexplo.exe
    2 %FontsDir%\tbh.ini
    3 %ProgramFiles%\Common Files\PushWare\cpush.dll
    4 %ProgramFiles%\Common Files\PushWare\Uninst.exe
    5 %ProgramFiles%\sovhst.exe
    6 %System%\dllcache\linkinfo.dll
    7 %Temp%\abb14.tmp
    8 %Temp%\abb9.tmp
    9 %Temp%\abbF.tmp
    10 %Temp%\dll1.tmp
    11 %Windir%\MICROSOFT\winsys.dll
    12 %Windir%\system\VGA13.dat
    13 %Windir%\Tasks\NSk5AtYYEPKtaSgzknZvW.ico
    14 c:\AUTORUN.INF
    15 c:\MZ.PIF

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL]
Loading...