Troj/Bifrose-VW is a Trojan for the Windows platform.
Troj/Bifrose-VW runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
When Troj/Bifrose-VW is installed the following files are created:
<Temp>\ixp000.tmp\gore-p~1.exe detected as Mal/Emogen-K
<Temp>\ixp000.tmp\postal~1.exe detected as Troj/Banhost-N
<Temp>\win32.exe detected as Troj/Bifrose-VW
<System>\IMG_SPA500135A.JPG.exe detected as Troj/Bifrose-VW
<System>\spoolvs.exe detected as Troj/Bifrose-VW
The following registry entry is created to run spoolvs.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
spoolvs
<System>\spoolvs.exe