Troj/Bifrose-CS is a Trojan for the Windows platform.
When first run Troj/Bifrose-CS copies itself to <System>\nerodll.exe.
The following registry entry is created to run nerodll.exe on startup:
HKLM\SOFTWARE\Microsoft\Active Setup\Installed
Components\(8B75D81C-C498-4935-C5D1-43AA4DB90836)
stubpath
<System>\nerodll.exe s
Troj/Bifrose-CS attempts to inject code into other processes in an attempt to
avoid detection.
Registry entries are created under:
HKCU\Software\Wget\