Home Malware Programs Backdoors Win-Trojan/Refroso.22016

Win-Trojan/Refroso.22016

Posted: July 30, 2009

Win-Trojan/Refroso.22016 is a dangerous backdoor Trojan horse. Win-Trojan/Refroso.22016 is likely to download or install other malware files without permission from the computer operator. Win-Trojan/Refroso.22016 is able to attack systems through the exploitation of local network shares. Win-Trojan/Refroso.22016 can also join a preset IRC server to contribute to DDos attacks.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %ProgramFiles%\Bifrost\server.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\BifrostHKEY_LOCAL_MACHINE\SOFTWARE\BifrostHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
Loading...