Trojan.
This one is nasty, heres my report. Rep if you appreciate
Files Created:
C:\Program Files\Bifrost
C:\Program Files\Bifrost\Server.exe
C:\WINDOWS\system32\drivers\ifkpr.sys
Services Created:
aic32p -> C:\WINDOWS\system32\drivers\ifkpr.sys
Auto Start Key:
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}
Mutex's Opened:
Bif1234
Op1mutx9
explorer.exeM_172_
Command/Control Server:
93.182.137.30:81
Writes to virtual memory of running processes.
Simply a crypted Bi-Frost server.
Last edited: