Threat Database Backdoors Backdoor.Win32.Poison.ajag

Backdoor.Win32.Poison.ajag

By ZulaZuza in Backdoors

Backdoor.Win32.Poison.ajag is a dangerous backdoor trojan virus that comes as attachment to email messages spammed by another malware or infected user in an attempt to monitor your system. Backdoor.Win32.Poison.ajag runs in the background and enables remote access to the affected PC system. Backdoor.Win32.Poison.ajag is also a keylogger program that can take over all user keystrokes involving personal details such username, password, credit card number. Backdoor.Win32.Poison.ajag opens up firewalls and gathers sensitive data such as personal financial information. Remove Backdoor.Win32.Poison.ajag immediately before it leads to further losses.

File System Details

Backdoor.Win32.Poison.ajag may create the following file(s):
# File Name Detections
1. %System%\Bifrost\server.exe
2. %System%\Bifrost\klog.dat
3. %PROGRAM_FILES%\Backdoor.Win32.Poison.ajag
4. %AppData%\addon.dat
5. C:\Documents and Settings\\Start Menu\Backdoor.Win32.Poison.ajag \
6. %AppData%\Microsoft\Crypto\RSA\S-1-5-21-606747145-764733703-839522115-1003\699c4b9cdebca7aaea5193cae8a50098_a7bcc1a4-f7a4-4502-8650-8579e607f7f7
7. C:\Documents and Settings\\Backdoor.Win32.Poison.ajag \

Registry Details

Backdoor.Win32.Poison.ajag may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
stubpath = "%System%\Bifrost\server.exe s"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}
HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo
HKEY_CURRENT_USER\Software\Bifrost
HKEY_LOCAL_MACHINE\Software\Backdoor.Win32.Poison.ajag

Trending

Most Viewed

Loading...