Home Malware Programs Trojans Troj/Bifrose-ZW

Troj/Bifrose-ZW

Posted: August 17, 2010

Troj/Bifrose-ZW is a malicious backdoor Trojan horse that runs in the background and allows remote access to the compromised system. Troj/Bifrose-ZW attempts to propagate by exploiting local network shares. Troj/Bifrose-ZW will also attempt to join a predefined IRC server to channel stolen data or participate in distributed denial-of-service (DDoS) attacks. The DDoS attacks will attempt to make the computer unavailable to its intended users. It is recommended that Troj/Bifrose-ZW be removed with a reliable anti-spyware application.

Aliases

Virus.Win32.Injector (Ikarus)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Bifrost\server.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}]
Loading...