Home Malware Programs Spyware Backdoor.Win32.Bifrose.fqm

Backdoor.Win32.Bifrose.fqm

Posted: February 25, 2011

The Trojan Backdoor.Win32.Bifrose.fqm is substantially more destructive than most of its cousins, with the potential to attack and delete critical files on your computer. Although Backdoor.Win32.Bifrose.fqm isn't a worm and can't infect computers through networks by itself, the Trojan may attach itself to another infection and propagate in that fashion. Backdoor.Win32.Bifrose.fqm will use registry alterations to run in the background, and will hide processes from the user so that you don't catch Backdoor.Win32.Bifrose.fqm even if you look for it in your Task Manager. Overall, as a threat this infection rates very severely, and you should delete Backdoor.Win32.Bifrose.fqm with an awareness of how drastic the potential damage can be for your machine.

Backdoor.Win32.Bifrose.fqm is a Unique but Invisible Malware Snowflake

Backdoor.Win32.Bifrose.fqm is a sneaky infection that prefers to couple itself with other malware to allow them to do all the work of infecting new systems. This is a notable difference from standard Backdoor.Bifrose threats, which are perfectly capable of worm-like infecting processes. New computers will be greeted by registry mutilation that ties Backdoor.Win32.Bifrose.fqm inextricably to the operating system's startup.

Backdoor.Win32.Bifrose.fqm will attempt to hide running processes from the user. This makes Task Manager inefficient at catching Backdoor.Win32.Bifrose.fqm, and removing Backdoor.Win32.Bifrose.fqm is best handled via good malware-removal software.

Less is Sometimes More (At Least With Regards to Computer Damage)

The majority of Trojans are happy enough to be spyware and not make a splash, but Backdoor.Win32.Bifrose.fqm is more aggressive than most. Instead of having any confirmed spying capabilities, Backdoor.Win32.Bifrose.fqm simply deletes preexisting files on your system, potentially including ones critical to running Windows. Such unusual behavior causes Backdoor.Win32.Bifrose.fqm to be an extreme danger to any computer that harbors Backdoor.Win32.Bifrose.fqm for any amount of time.

Settings its file-eating tendencies aside, Backdoor.Win32.Bifrose.fqm is equally dangerous as a backdoor-enabler. By creating security holes Backdoor.Win32.Bifrose.fqm allows remote attackers to access your computer directly. Remote attackers may choose to take control of your computer, to spy on the contents of your files or even merely drop more malware on top of what you're already struggling to beat.

Failing to delete Backdoor.Win32.Bifrose.fqm in time is likely to result in more malware being installed regardless of any other problems you may experience. Such malware includes spyware that snatches up passwords and account logins, rogue products that deluge you with a flurry of fake errors and alerts and other destructive theats. No matter how quickly you want Backdoor.Win32.Bifrose.fqm gone, though, stay calm during the deletion process. Given Backdoor.Win32.Bifrose.fqm's tendency to bundle itself with other malware, missing even one component could make all your hard work in vain.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %
    2 %appdata%\microsoft\internet explorer\quick launch\Backdoor.Win32.Bifrose.fqm.lnk
    3 %commonprograms%\Backdoor.Win32.Bifrose.fqm\about.lnk
    4 %commonprograms%\Backdoor.Win32.Bifrose.fqm\activate.lnk
    5 %commonprograms%\Backdoor.Win32.Bifrose.fqm\Backdoor.Win32.Bifrose.fqm support.lnk
    6 %commonprograms%\Backdoor.Win32.Bifrose.fqm\Backdoor.Win32.Bifrose.fqm.lnk
    7 %commonprograms%\Backdoor.Win32.Bifrose.fqm\buy.lnk
    8 %commonprograms%\Backdoor.Win32.Bifrose.fqm\scan.lnk
    9 %commonprograms%\Backdoor.Win32.Bifrose.fqm\settings.lnk
    10 %commonprograms%\Backdoor.Win32.Bifrose.fqm\update.lnk
    11 %desktop%\Backdoor.Win32.Bifrose.fqm support.lnk
    12 %desktop%\Backdoor.Win32.Bifrose.fqm.lnk
    13 %programfiles\Backdoor.Win32.Bifrose.fqm\activate.ico
    14 %programfiles\Backdoor.Win32.Bifrose.fqm\buy.ico
    15 %programfiles\Backdoor.Win32.Bifrose.fqm\def.db
    16 %programfiles\Backdoor.Win32.Bifrose.fqm\defcnt.exe
    17 %programfiles\Backdoor.Win32.Bifrose.fqm\defext.dll
    18 %programfiles\Backdoor.Win32.Bifrose.fqm\defhook.dll
    19 %programfiles\Backdoor.Win32.Bifrose.fqm\scan.ico
    20 %programfiles\Backdoor.Win32.Bifrose.fqm\settings.ico
    21 %programfiles\Backdoor.Win32.Bifrose.fqm\splash.mp3
    22 %programfiles\Backdoor.Win32.Bifrose.fqm\uninstall.exe
    23 %programfiles\Backdoor.Win32.Bifrose.fqm\update.ico
    24 %programfiles\Backdoor.Win32.Bifrose.fqm\virus.mp3
    25 programfiles\Backdoor.Win32.Bifrose.fqm\about.ico
    26 programfiles\Backdoor.Win32.Bifrose.fqm\help.ico

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}hkcu\Software\Microsoft\Windows\CurrentVersion\Run "Backdoor.Win32.Bifrose.fqm"hklm\SOFTWARE\Backdoor.Win32.Bifrose.fqmHKEY..\..\..\..{RegistryKeys}hkcr\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Backdoor.Win32.Bifrose.fqm
Loading...