CDNUPLIB.DLL – Backdoor Bifrose

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

CDNUPLIB.DLL – Backdoor Bifrose removal

FileMD5Virus Alias
CDNUPLIB.DLL 3e652cfaa415b616c07a3cc361e975ce Backdoor Bifrose

CDNUPLIB.DLL size: 160320 bytes
CDNUPLIB.DLL hash: 3E652CFAA415B616C07A3CC361E975CE

Created files:

%TEMP%\2vns3s.dll
%TEMP%\33\cdn.dll
%TEMP%\33\cdnaux.dll
%TEMP%\33\cdncmd.dll
%TEMP%\33\cdncol.dll
%TEMP%\33\cdndet.dll
%TEMP%\33\cdndrag.dll
%TEMP%\33\cdnforie.dll
%TEMP%\33\cdnins.dll
%TEMP%\33\cdnns.dll
%TEMP%\33\cdnprh.dll
%TEMP%\33\cdnprot.sys
%TEMP%\33\cdnsign.dll
%TEMP%\33\cdntdns.dll
%TEMP%\33\cdntran.sys
%TEMP%\33\cdnuc.exe
%TEMP%\33\cdnunins.exe
%TEMP%\33\cdnup.exe
%TEMP%\33\cdnuplib.dll
%TEMP%\33\client.dll
%TEMP%\33\idnconv.dll
%TEMP%\33\iesrch.dll
%TEMP%\33\imaoe.dll
%TEMP%\33\rbtnhtm.cab
%TEMP%\33\setup.exe
%TEMP%\33\wmhlpr.dll
%TEMP%\cijbdswwkb
%TEMP%\r6qqyl.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\cijbdsw\Type: 01000000
HKLM\System\CurrentControlSet\Services\cijbdsw\Start: 03000000
HKLM\System\CurrentControlSet\Services\cijbdsw\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\cijbdsw\DisplayName: cijbdsw
HKLM\System\CurrentControlSet\Services\cijbdsw\ImagePath: %TEMP%\cijbdswwkb

Detected by UnHackMe:

CDNUPLIB.DLL
Default location: %TEMP%\33\CDNUPLIB.DLL

Dropper information:
MD5: 239831e7cf8be91748bd79c16f8eeea2
File size: 670208 bytes

Leave a Reply