Home Malware Programs Trojans Trojan.Win32.Refroso.ccoo

Trojan.Win32.Refroso.ccoo

Posted: February 25, 2011

Between messages with flash file attachments and infections bundled with small P2P-distributed applications, the unusual methods by which Trojan.Win32.Refroso.ccoo gains access to systems may take some by surprise. The Trojan.Win32.Refroso.ccoo Trojan is as dangerous as most of its ilk, poking holes in security to allow access by remote attackers and malicious file downloads. This Trojan may or may not choose to disguise itself as an obvious application, and a legitimate anti-malware software are best-equipped to deal with any necessary Trojan.Win32.Refroso.ccoo-deleting sweeps for certainty of accurate and thorough eradication.

Earning Your Distrust Through Corrupt Applications

Trojan.Win32.Refroso.ccoo is just like all the other Trojans out there in that Trojan.Win32.Refroso.ccoo doesn't use straightforward vectors for infection. P2P files and other widely-distributed executables are likely to be infected, and there have been documented cases of serial and key generator applications being infected by Trojan.Win32.Refroso.ccoo. Avoiding piracy-related applications will keep you further away from Trojan.Win32.Refroso.ccoo, but if you must download such a file, do yourself a favor and give it a good virus scan first.

Trojan.Win32.Refroso.ccoo can spread itself through message-based electronic mediums as well. In this case Trojan.Win32.Refroso.ccoo's usually spotted as a flash file attachment, which naturally shouldn't be downloaded or executed.

Computers that host Trojan.Win32.Refroso.ccoo may do so with little knowledge of the user due to the Trojan running in the background. Trojan.Win32.Refroso.ccoo has been reported to alter the registry, which can be used to run the program without revealing its presence. Another more unusual trick Trojan.Win32.Refroso.ccoo may use is to disguise itself as a genuine application, such as a Yahoo emoticons generator. Even if the application itself is functional, the Trojan.Win32.Refroso.ccoo infection will still be making its attacks.

Watch Trojan.Win32.Refroso.ccoo Grab Onto Anything It Can to Do Damage With

The Trojan.Win32.Refroso.ccoo infection will retain all the damaging traits of basic Refroso-subtype Trojans and may also make more individualized hostile efforts.

  • Trojan.Win32.Refroso.ccoo will lower your security and allow remote access by unauthorized third parties. These parties may then transfer files in either direction or completely take over the input of your machine.
  • Trojan.Win32.Refroso.ccoo may monitor the applications being run on your computer or spy on other activities that pass through the machine. This can include keyboard input and information stored on files such as account passwords.
  • Trojan.Win32.Refroso.ccoo, being a Trojan, is very likely to drop extra hostile programs onto your computer.

No Trojan should be tolerated on any computer that needs to be safe and stable, and Trojan.Win32.Refroso.ccoo is no different from the rest. Delete Trojan.Win32.Refroso.ccoo personally if you have the ability to do so, or if necessary, seek out relevant anti-malware programs to do it in your stead.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Bifrost\server.exe
    2 %Windir%\Camfrog Name Serials [ Beta ].exe
    3 %Windir%\Camfrog Serials.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\BifrostHKEY_CURRENT_USER\Software\BifrostHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SOFTWARE\BifrostHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
Loading...