Trojan-Dropper.Win32.Agent.xzr
Trojan-Dropper.Win32.Agent.xzr is a malicious backdoor trojan that runs in the background and enables a hacker remote access to the targeted computer system. Trojan-Dropper.Win32.Agent.xzr initiates automatically when computer boots up because it has dropped its start-up item in the registry entry. Trojan-Dropper.Win32.Agent.xzr will download files to the computer without a victim's consent which will lead to security threat. Trojan-Dropper.Win32.Agent.xzr can propagate via network if the malicious drive is shared at the network.
File System Modifications
- The following files were created in the system:
# File Name 1 %ProgramFiles%\Bifrost\server.exe 2 %System%\molebox.exe 3 %System%\server1.exe
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\032HKEY_LOCAL_MACHINE\SOFTWARE\032HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.