Threat Database Backdoors Backdoor.Win32.Bifrose.ahyw

Backdoor.Win32.Bifrose.ahyw

By GoldSparrow in Backdoors

Backdoor.Win32.Bifrose.ahyw is a damaging Trojan infection that penetrates into your computer without your consent or knowledge by using security exploits. Backdoor.Win32.Bifrose.ahyw has been known to download adware or corrupt files onto your computer. Backdoor.Win32.Bifrose.ahyw can replicate itself, disable security applications from being deleted, change system settings and collect personal information for a remote attacker. Backdoor.Win32.Bifrose.ahyw may refer to an application that seems to be something you may think is safe. Backdoor.Win32.Bifrose.ahyw may also be some type of image or audio or video files that would attract you or force you to open them. You can receive those malicious files through email as attachments.

File System Details

Backdoor.Win32.Bifrose.ahyw may create the following file(s):
# File Name Detections
1. %System%\dllcache\termsrvhack.dll
2. %System%\termsrvhack.dll

Registry Details

Backdoor.Win32.Bifrose.ahyw may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RDPWD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RDPWD\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RDPWD\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RDPWD\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDTCP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_RDPWD
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDTCP\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RDPWD
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDTCP\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDTCP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDTCP\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDTCP

Trending

Most Viewed

Loading...