Home Malware Programs Trojans Trojan.Win32.Refroso.diyb

Trojan.Win32.Refroso.diyb

Posted: July 4, 2011

Trojan.Win32.Refroso.diyb is a Trojan that conceals memory processes to engage in malicious activities without being seen. Typically, this is a sign of a backdoor Trojan that allows remote attackers to control your PC, although it may also be indicative of a dropper Trojan that installs harmful programs without allowing a criminal to have direct control. In either case, Trojan.Win32.Refroso.diyb is an incredibly severe security and privacy threat. You shouldn't try to find or remove Trojan.Win32.Refroso.diyb without anti-malware software, since advanced Trojan threats such as Trojan.Win32.Refroso.diyb can easily avoid manual deletion attempts.

The Rundown on Trojan.Win32.Refroso.diyb

As a threat with limited distribution and minimal symptoms reported, Trojan.Win32.Refroso.diyb's aliases consist of generic detections such as VirTool:Win32/VBInject.gen!ET and Gen.Heur. These alternate detection names are based on Trojan.Win32.Refroso.diyb's basic structure, which obscures Trojan.Win32.Refroso.diyb's code via encryption and a Visual Basic loader. Since a loader like the one Trojan.Win32.Refroso.diyb uses can be put to virtually any purpose, Trojan.Win32.Refroso.diyb's behavior may vary slightly or even significantly from one infection incident to the next one.

Trojan.Win32.Refroso.diyb has been known to launch and conceal iexplore.exe (or Internet Explorer) memory processes; this may be an attempt to hide browser hijack-related attacks or exploits, which can include pop-up creation, redirecting your browser to strange websites or monitoring information such as website traffic.

Some Trojan.Win32.Refroso.diyb infections have also been seen to make significant additions to the Windows Registry. This tactic often results in the automatic launch of threats like Trojan.Win32.Refroso.diyb or in programs being disabled, but Registry changes can also perform other harmful actions. Changing the Registry without the help of an expert or highly advanced security software is strongly discouraged, since improper alterations to the Windows Registry can cause serious damage to Windows.

A Clear Look at Trojan.Win32.Refroso.diyb's Merciless Possibilities for Your PC

Some common risks associated with Trojan attackers like Trojan.Win32.Refroso.diyb include:

  • Trojan.Win32.Refroso.diyb may disable your firewall and other security programs by deleting the relevant Registry entries or by attacking these applications in other ways. The primary purpose of this Trojan.Win32.Refroso.diyb attack is to allow unfettered traffic between Trojan.Win32.Refroso.diyb and remote criminals.
  • In lieu of disabling your programs, Trojan.Win32.Refroso.diyb may choose to alter the settings so that they're ineffective as obstacles against Trojan.Win32.Refroso.diyb's attacks. Commonly, this includes adding exceptions to the Windows Firewall.
  • Trojan.Win32.Refroso.diyb may download or contain components for a Remote Administration Tool (also known as a RAT) or other means of allowing outside access to your PC This is a typical method of accomplishing remote attacks, which can result in DDoS crimes and self-destructive actions for your computer.
  • In addition to all these possibilities, Trojan.Win32.Refroso.diyb may also add many other PC threats to your computer by installing other harmful software. This often includes keyloggers that steal passwords and other private information, scamware that fake being legitimate products, browser hijackers, worms and viruses.

It's difficult to overstate how essential removing Trojan.Win32.Refroso.diyb is to your computer's safety, but this process should always use a good anti-virus program if you have access to one.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\addons.dat

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\BifrostHKEY_LOCAL_MACHINE\SOFTWARE\BifrostHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
Loading...