Backdoor Bifrose – vynnuu.exe – 63fb589c109bca1600ae4c1c21e64b99

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Backdoor Bifrose
Also known as: Trojan Generic, Trojan Magania
SHA256: fe418372fe38abaf28d863e2ad5d552776636c73ca28da4d56da04931d7a54bf
SHA1: c9c1be10b84f986725851ac633774e033befc071
MD5: 63fb589c109bca1600ae4c1c21e64b99
File size: 135168 bytes

Created files:

%SysDir%\vynnuu.exe – Backdoor Bifrose
%WinDir%\TEMP\Server.dll – Backdoor Bifrose

Backdoor Bifrose created autostart registry keys:

HKLM\System\CurrentControlSet\Services\BITS\JConnectGroup: 7+bu7ODl7uzo6KugoJ+fq+zf9JeVlZWVzQ==
HKLM\System\CurrentControlSet\Services\BITS\JSet: รป??????
HKLM\System\CurrentControlSet\Services\BITS\JTime: 253
HKLM\System\CurrentControlSet\Services\dke qec\Type: 10000000
HKLM\System\CurrentControlSet\Services\dke qec\Start: 02000000
HKLM\System\CurrentControlSet\Services\dke qec\DisplayName: ouq vcg ffo
HKLM\System\CurrentControlSet\Services\dke qec\ImagePath: %WinDir%\System32\vynnuu.exe
HKLM\System\CurrentControlSet\Services\dke qec\Description: lyr etn pbw psq fhr.

Leave a Reply