Home Malware Programs Trojans Trojan.Win32.Refroso.dehx

Trojan.Win32.Refroso.dehx

Posted: September 7, 2011

Threat Metric

Threat Level: 9/10
Infected PCs: 97
First Seen: September 7, 2011
OS(es) Affected: Windows

Trojan.Win32.Refroso.dehx is a seditious Trojan infection that can access a targeted computer system secretly via P2P. Trojan.Win32.Refroso.dehx conceals itself in other system files, hides in the background and uses malicious techniques to download and install other malware threats. Trojan.Win32.Refroso.dehx can monitor its victim's Internet activities for commercial purpose. Trojan.Win32.Refroso.dehx also compromises a user's personal information and forwards it to remote attackers. You should delete Trojan.Win32.Refroso.dehx immediately upon detection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



xDs.7x.exe File name: xDs.7x.exe
Size: 105.75 KB (105754 bytes)
MD5: 9bae1bafac4541f0adf07afa85a8c73f
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 10, 2011
%ProgramFiles%\BifroXx\server.exe File name: %ProgramFiles%\BifroXx\server.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideoHKEY_CURRENT_USER\Software\BifroXxHKEY_LOCAL_MACHINE\SOFTWARE\BifroXxHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo
Loading...