Sophos

Troj/Bifrose-CH

Aliases
  • Backdoor.Win32.Bifrose.d
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from February 2006 (4.02)
Protection available since 28 December 2005 08:42:26 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Bifrose-CH is a Trojan for the Windows platform.

When run, Troj/Bifrose-CH copies itself to <Windows>\svchost.exe and creates the file <Windows>\plugin1.dat. The file plugin1.dat can be deleted safely.

When run, Troj/Bifrose-CH sets the following registry entries:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
F-Secure 2005
<Windows>\svchost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
F-Secure 2005
<Windows>\svchost.exe

HKCU\Software\Wget\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer