Home Malware Programs Trojans Trojan.Win32.Pincav.oqd

Trojan.Win32.Pincav.oqd

Posted: March 12, 2010

Trojan.Win32.Pincav.oqd is a malicious backdoor Trojan that runs in the background. Trojan.Win32.Pincav.oqd disables the firewall and attempts to steal sensitive financial data like credit card numbers, online banking login details. Trojan.Win32.Pincav.oqd creates a startup registry entry that loads as soon as Windows is booted. Trojan.Win32.Pincav.oqd is a malicious trojan horse that may represent a severe security risk for the compromised system and should be removed immediately.

Aliases

VirTool:Win32/VBInject.gen!BP (Microsoft)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Bifrost\logg.dat
    2 %ProgramFiles%\Bifrost\server.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}]
Loading...