Home
/
Spyware Encyclopedia
/ Backdoor.Bifrost
Backdoor.Bifrost Technical Details
Category
Backdoor
Discovered
7/2/2007 5:25:00 PM
Modified
7/2/2007 5:45:00 PM
Threat Level
Medium
Description
A Backdoor is a software program that gives an attacker unauthorized access to a machine and the means for remotely controlling the machine without the user's knowledge. A Backdoor compromises system integrity by making changes to the system that allow it to be used by the attacker for malicious purposes unknown to the user.
Summary
The hosts file was updated with the following url-to-ip mappings:
n/a
The following http urls were started:
agriturismo-grugliasco.esf-wiki.org
landing.domainsponsor.com
ads.kw.revenue.net
Generated smtp traffic:
n/a
Connection(s) established with remote IRC Server:
n/a
The following hidden entries created:
hidden process: c:\program files\internet explorer\iexplore.exe
%SYSDIR%\kdlht.exe
The following internet connection was established:
68.178.211.72:1047(winhostecn72.prod.mesa1.secureserver.net)
222.82.137.74:1981
198.65.119.21:80
When the Backdoor is executed, it creates the following files:
Name
Version
Publisher
Signature (MD5)
File Size (in Bytes)
..\bifrost\server.exe
1819e57df0f53edfb7715e85be8bc791
146811
..\web-codec1211.exe
9037c9ed1c554dd7dc2d353de886fea7
..\setup.exe
24acd1d326724b71c585945dc96f4ce6
..\11190934271.exe
100D7E8B60C0F8B82E720E40D822CD50
..\4dfc4766.dll
dafe360973924656f88d60fceb6fb74e
..\75e8fa9e.exe
0.0.0.0
microsoft corporation
6cb19f51087fa288268da2249d894e61
17812
..\bifrost\server.exe
100d7e8b60c0f8b82e720e40d822cd50
29053
..\kdlht.exe
..\mvnzax.dll
5f72bb2ea6a35e17726b1e625e688d00
16896
..\upnpsvc.exe
5.1.2600.2180
microsoft corporatio
a6f6ccce3eee78b09563f624c6c0db19
64512
When the Backdoor is executed, it creates the following Registry entries:
•
..\software\vifr0st
•
..\system\currentcontrolset\services\bc99eb31
•
..\software\microsoft\active setup\installed components\{1c67b55f-d1be-a9de-2bee-d7dee088c5b6}
•
..\software\microsoft\windows\currentversion\run\"was_check"
•
..\software\vifr0st
Recommendation to remove Backdoor.Bifrost
Spyware Detector can remove Backdoor.Bifrost, and thousands of other Spyware definitions, automatically and instantly.
Click here
to download Spyware Detector and scan for free.
Personalized e-Mail support
by our Research Team. You send an "Export Log" report to us, we then add new definition and you eliminate spyware found on YOUR PC in the next Live Update. So, not only do you benefit but the whole community enjoys the feedback.
Speed up your computer
and increase browsing performance by deleting Spyware & Adware
Enjoy continuous protection and security with
frequent spyware definition updates
so you never have to worry about new threats and outdated software.
Surf the web with confidence
knowing your online activities aren't being tracked, and your
confidential data is secure
from prying eyes.
Search Threats
Testimonials
Read More
Information Desk
Spyware & Adware Categories we scan
List of Spyware &
Adware we remove
Submit a Threat
Submit a threat to be reviewed by our research team
Submit a Threat
Home
|
About Us
|
Purchase
|
Contact Us
|
FAQ
|
Privacy Policy