Home Malware Programs Trojans Trojan.Win32.Refroso.cxc

Trojan.Win32.Refroso.cxc

Posted: October 27, 2009

Trojan.Win32.Refroso.cxc is a destructive and malicious trojan designed to steal information from an infected system and send the compromised data to a remote server. Trojan.Win32.Refroso.cxc, or Trojan-Spy.Win32.VB, may open a security hole that allows the download and installation of malware programs onto an infected system. Aside from gathering system information, Trojan-Trojan.Win32.Refroso.cxc may initiate computer performance problems. Trojan.Win32.Refroso.cxc is a security risk and should be removed.

Aliases

Trojan-Spy.Win32.VB (Ikarus)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\data\data32.exe
    2 %System%\data\logg.dat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\system32HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{1830D8F5-834A-13C4-38C9-2041E933D1D5}HKEY_LOCAL_MACHINE\SOFTWARE\system32HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
Loading...