Home Malware Programs Trojans Trojan.Win32.Chifrax.cmb

Trojan.Win32.Chifrax.cmb

Posted: June 30, 2011

Trojan.Win32.Chifrax.cmb is a Trojan that's often found in the company of other Trojans that attack your security. Trojan.Win32.Chifrax.cmb may also attack your PC security and can hide memory processes and launch itself on Windows startup. Some Trojan.Win32.Chifrax.cmb infections have also been seen making unauthorized contact with websites, requesting information from third parties and sending information without your consent. The presence of any Trojan.Win32.Chifrax.cmb infection on your PC is a high-level security and privacy invasion and you should delete Trojan.Win32.Chifrax.cmb threats with the use of an equally powerful anti-virus program.

Trojan.Win32.Chifrax.cmb and Its Not-So-Friendly Trojan Acquaintances

More often than not, if you're infected with Trojan.Win32.Chifrax.cmb, it is not the only infection you need to worry about on your computer. Most Trojan.Win32.Chifrax.cmb infections have been seen alongside other Trojan threats, particularly Backdoor.Bifrose. Bifrose is a backdoor Trojan that attacks your security to recruit your computer into illegal Denial-of-Service activities and can even spread through network-shared resources.

Like Bifrose, Trojan.Win32.Chifrax.cmb will try to hide Trojan.Win32.Chifrax.cmb's actions and may even conceal Trojan.Win32.Chifrax.cmb's own memory processes. Trojan.Win32.Chifrax.cmb files are usually placed in a subdirectory of your Windows folder and will launch themselves automatically whenever Windows runs.

To protect yourself from possible Trojan.Win32.Chifrax.cmb infections, exercise caution around file sources from Russia and Iran; both of these countries have been confirmed as sources of Trojan.Win32.Chifrax.cmb infections.

Most Trojan.Win32.Chifrax.cmb infections are also bundled with installation utilities, sometimes even for legitimate programs like WinRAR. Always download installation files from legitimate websites to reduce any possible chance of being attacked by Trojan.Win32.Chifrax.cmb.

If Trojan.Win32.Chifrax.cmb Attacks, What to Watch Out For

Trojan.Win32.Chifrax.cmb may engage in a variety of harmful actions, but Trojan.Win32.Chifrax.cmb's most prominent activities include:

  • Making contact with external websites without your permission.
  • Sending information to outside parties, potentially including information that could be used to attack your PC, such as IP addresses, or private information like account login passwords.
  • Requesting information from remote parties, potentially to harm your computer or reconfigure itself for other attacks.

These actions may not leave visible signs of their ongoing activities, although you may notice an opened port, exceptions added to your firewall or unusual network activity, if you monitor your PC network activity for such issues. All of these actions may cause Trojan.Win32.Chifrax.cmb to take up significant memory and bandwidth, which can slow your computer down and cause other system problems.

Trojan.Win32.Chifrax.cmb may also install harmful programs, serve as the first part in a multi-step process that lets remote criminals take over your PC, force your computer to engage in DDoS attacks or attack your security applications and settings. You can remove Trojan.Win32.Chifrax.cmb with appropriate anti-malware software and should do so immediately, since any Trojan.Win32.Chifrax.cmb infection is a significant security threat.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\Bifrost\logg.dat
    2 %System%\Bifrost\server.exe
    3 %Windir%\Nashy.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\BifrostHKEY_CURRENT_USER\Software\WinRAR SFXHKEY_LOCAL_MACHINE\SOFTWARE\BifrostHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
Loading...