TSUSBREDIRECTIONGROUPPOLICYEXTENSION.EXE – Backdoor Bifrose

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

TSUSBREDIRECTIONGROUPPOLICYEXTENSION.EXE – Backdoor Bifrose removal

FileMD5Virus Alias
TSUSBREDIRECTIONGROUPPOLICYEXTENSION.EXE 62d5f6665f208ef1692fba60eebf75bc Backdoor Bifrose
TSUSBREDIRECTIONGROUPPOLICYEXTENSION.EXE 62d5f6665f208ef1692fba60eebf75bc Trojan CI
TSUSBREDIRECTIONGROUPPOLICYEXTENSION.EXE 62d5f6665f208ef1692fba60eebf75bc Trojan ZBot
TSUSBREDIRECTIONGROUPPOLICYEXTENSION.EXE 62d5f6665f208ef1692fba60eebf75bc Trojan Jorik

TSUSBREDIRECTIONGROUPPOLICYEXTENSION.EXE size: 81408 bytes

Created files:

%AppData%\-692465845
%Local AppData%\Microsoft\Windows\1451\d6b9cf4b
%Local AppData%\Microsoft\Windows\1451\TsUsbRedirectionGroupPolicyExtension.exe

Autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\TsUsbRedirectionGroupPolicyExtension: %WinDir%\System32\config\Systemprofile\Local Settings\Application Data\Microsoft\Windows\1451\TsUsbRedirectionGroupPolicyExtension.exe

Detected by UnHackMe:

TSUSBREDIRECTIONGROUPPOLICYEXTENSION.EXE
Default location: %LOCAL APPDATA%\MICROSOFT\WINDOWS\1451\TSUSBREDIRECTIONGROUPPOLICYEXTENSION.EXE

Leave a Reply