Threat Database Trojans Constructor.Win32.Bifrose.gy

Constructor.Win32.Bifrose.gy

By JubileeX in Trojans

Constructor.Win32.Bifrose.gy is a harmful Trojan which can be used by hackers to harm a computer system. Constructor.Win32.Bifrose.gy changes system Hosts file to block the corrupted PC system from logging to security websites. Constructor.Win32.Bifrose.gy enables additional parasites to be downloaded to the corrupted machine, steals personal information from the targeted Internet user and slows down computer running. Constructor.Win32.Bifrose.gy may connect with a remote hacker to download infected files which may cause network and program load slowly. You should eliminate Constructor.Win32.Bifrose.gy from the affected computer system as soon as possible upon detection.

File System Details

Constructor.Win32.Bifrose.gy may create the following file(s):
# File Name Detections
1. %Windir%\msf\msf.exe
2. %Temp%\Setup.exe
3. %Temp%\Bifrost.exe
4. %AppData%\logs.dat
5. %Windir%\HOSTS
6. %Temp%\XxX.xXx

Registry Details

Constructor.Win32.Bifrose.gy may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\BIFROST1.2
HKEY_CURRENT_USER\Software\WinRAR SFX
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{10B16I71-RVF2-6GNQ-DIIC-7015LW1M4GIG}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
HKEY_CURRENT_USER\Software\BIFROST1.2\DIALOG\0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host
HKEY_CURRENT_USER\Software\BIFROST1.2\DIALOG
HKEY_CURRENT_USER\Software\][Timarz]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo

Trending

Most Viewed

Loading...