Trojan.Win32.Pakes.oxy
Trojan.Win32.Pakes.oxy is a Trojan that allows Internet attackers to remotely access and monitor a PC. Trojan.Win32.Pakes.oxy can steal your personal information and send it to remote attackers. Trojan.Win32.Pakes.oxy adds it start-up registry entry so that it could run automatically every time you start your computer. Once Trojan.Win32.Pakes.oxy is installed on your PC, it will reduce your PC performance and slow down your computer. Uninstall Trojan.Win32.Pakes.oxy immediately upon detection before it harms your computer system.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:%ProgramFiles%\Bifrost\lol.exe
File name: %ProgramFiles%\Bifrost\lol.exeSize: 62B (62 bytes)
MD5: 0xDBCBD7D171081EA92EA7488DAD881C
File type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Internet Explorer\Connection Wizard\inetwiz.exe
File name: %ProgramFiles%\Internet Explorer\Connection Wizard\inetwiz.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Internet Explorer\Connection Wizard\isignup.exe
File name: %ProgramFiles%\Internet Explorer\Connection Wizard\isignup.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Internet Explorer\Connection Wizard\icwconn1.exe
File name: %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn1.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Internet Explorer\Connection Wizard\icwconn2.exe
File name: %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn2.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Internet Explorer\Connection Wizard\icwrmind.exe
File name: %ProgramFiles%\Internet Explorer\Connection Wizard\icwrmind.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Internet Explorer\Connection Wizard\icwtutor.exe
File name: %ProgramFiles%\Internet Explorer\Connection Wizard\icwtutor.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Internet Explorer\iedw.exe
File name: %ProgramFiles%\Internet Explorer\iedw.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Internet Explorer\IEXPLORE.EXE
File name: %ProgramFiles%\Internet Explorer\IEXPLORE.EXEFile type: Executable File
Mime Type: unknown/EXE
%ProgramFiles%\MSN\MSNIA\msniasvc.exe
File name: %ProgramFiles%\MSN\MSNIA\msniasvc.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\MSN\MSNIA\prestp.exe
File name: %ProgramFiles%\MSN\MSNIA\prestp.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\MSN\MsnInstaller\msninst.exe
File name: %ProgramFiles%\MSN\MsnInstaller\msninst.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\NetMeeting\conf.exe
File name: %ProgramFiles%\NetMeeting\conf.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\NetMeeting\cb32.exe
File name: %ProgramFiles%\NetMeeting\cb32.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\NetMeeting\wb32.exe
File name: %ProgramFiles%\NetMeeting\wb32.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Windows Media Player\mplayer2.exe
File name: %ProgramFiles%\Windows Media Player\mplayer2.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Windows Media Player\migrate.exe
File name: %ProgramFiles%\Windows Media Player\migrate.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Windows Media Player\setup_wm.exe
File name: %ProgramFiles%\Windows Media Player\setup_wm.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Windows Media Player\wmplayer.exe
File name: %ProgramFiles%\Windows Media Player\wmplayer.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Outlook Express\msimn.exe
File name: %ProgramFiles%\Outlook Express\msimn.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Outlook Express\oemig50.exe
File name: %ProgramFiles%\Outlook Express\oemig50.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Outlook Express\setup50.exe
File name: %ProgramFiles%\Outlook Express\setup50.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Outlook Express\wab.exe
File name: %ProgramFiles%\Outlook Express\wab.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Outlook Express\wabmig.exe
File name: %ProgramFiles%\Outlook Express\wabmig.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Web Publish\WPWIZ.EXE
File name: %ProgramFiles%\Web Publish\WPWIZ.EXEFile type: Executable File
Mime Type: unknown/EXE
%ProgramFiles%\Windows NT\Accessories\wordpad.exe
File name: %ProgramFiles%\Windows NT\Accessories\wordpad.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Windows NT\dialer.exe
File name: %ProgramFiles%\Windows NT\dialer.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Windows NT\hypertrm.exe
File name: %ProgramFiles%\Windows NT\hypertrm.exeFile type: Executable File
Mime Type: unknown/exe
%ProgramFiles%\Windows NT\Pinball\PINBALL.EXE
File name: %ProgramFiles%\Windows NT\Pinball\PINBALL.EXEFile type: Executable File
Mime Type: unknown/EXE
%Windir%\Cache\Adobe Reader 6.0.1\ENUBIG\setup.exe
File name: %Windir%\Cache\Adobe Reader 6.0.1\ENUBIG\setup.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\msagent\agentsvr.exe
File name: %Windir%\msagent\agentsvr.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\mui\muisetup.exe
File name: %Windir%\mui\muisetup.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\NOTEPAD.EXE
File name: %Windir%\NOTEPAD.EXEFile type: Executable File
Mime Type: unknown/EXE
%Windir%\pchealth\helpctr\binaries\msconfig.exe
File name: %Windir%\pchealth\helpctr\binaries\msconfig.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\pchealth\helpctr\binaries\notiflag.exe
File name: %Windir%\pchealth\helpctr\binaries\notiflag.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\pchealth\UploadLB\Binaries\UploadM.exe
File name: %Windir%\pchealth\UploadLB\Binaries\UploadM.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\pchealth\helpctr\binaries\HelpCtr.exe
File name: %Windir%\pchealth\helpctr\binaries\HelpCtr.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\pchealth\helpctr\binaries\HelpHost.exe
File name: %Windir%\pchealth\helpctr\binaries\HelpHost.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\pchealth\helpctr\binaries\HelpSvc.exe
File name: %Windir%\pchealth\helpctr\binaries\HelpSvc.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\pchealth\helpctr\binaries\HscUpd.exe
File name: %Windir%\pchealth\helpctr\binaries\HscUpd.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\hh.exe
File name: %Windir%\hh.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\inf\unregmp2.exe
File name: %Windir%\inf\unregmp2.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Installer\{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}\places.exe
File name: %Windir%\Installer\{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}\places.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\NETFXSBS10.exe
File name: %Windir%\Microsoft.NET\Framework\NETFXSBS10.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe
File name: %Windir%\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\CasPol.exe
File name: %Windir%\Microsoft.NET\Framework\v2.0.50727\CasPol.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe
File name: %Windir%\Microsoft.NET\Framework\v2.0.50727\dfsvc.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\IEExec.exe
File name: %Windir%\Microsoft.NET\Framework\v2.0.50727\IEExec.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe
File name: %Windir%\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe
File name: %Windir%\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe
File name: %Windir%\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe
File name: %Windir%\Microsoft.NET\Framework\v2.0.50727\MSBuild.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe
File name: %Windir%\Microsoft.NET\Framework\v2.0.50727\RegAsm.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
File name: %Windir%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\Microsoft.NET\Framework\v2.0.50727\jsc.exe
File name: %Windir%\Microsoft.NET\Framework\v2.0.50727\jsc.exeFile type: Executable File
Mime Type: unknown/exe
%Windir%\regedit.exe
File name: %Windir%\regedit.exeFile type: Executable File
Mime Type: unknown/exe
%System%\attrib.exe
File name: %System%\attrib.exeFile type: Executable File
Mime Type: unknown/exe
%System%\auditusr.exe
File name: %System%\auditusr.exeFile type: Executable File
Mime Type: unknown/exe
%System%\accwiz.exe
File name: %System%\accwiz.exeFile type: Executable File
Mime Type: unknown/exe
%System%\actmovie.exe
File name: %System%\actmovie.exeFile type: Executable File
Mime Type: unknown/exe
%System%\asr_pfu.exe
File name: %System%\asr_pfu.exeFile type: Executable File
Mime Type: unknown/exe
%System%\at.exe
File name: %System%\at.exeFile type: Executable File
Mime Type: unknown/exe
%System%\atmadm.exe
File name: %System%\atmadm.exeFile type: Executable File
Mime Type: unknown/exe
%System%\ahui.exe
File name: %System%\ahui.exeFile type: Executable File
Mime Type: unknown/exe
%System%\arp.exe
File name: %System%\arp.exeFile type: Executable File
Mime Type: unknown/exe
%System%\asr_fmt.exe
File name: %System%\asr_fmt.exeFile type: Executable File
Mime Type: unknown/exe
%System%\asr_ldm.exe
File name: %System%\asr_ldm.exeFile type: Executable File
Mime Type: unknown/exe
%System%\blastcln.exe
File name: %System%\blastcln.exeFile type: Executable File
Mime Type: unknown/exe
%System%\bootcfg.exe
File name: %System%\bootcfg.exeFile type: Executable File
Mime Type: unknown/exe
%System%\bootok.exe
File name: %System%\bootok.exeFile type: Executable File
Mime Type: unknown/exe
%System%\bootvrfy.exe
File name: %System%\bootvrfy.exeFile type: Executable File
Mime Type: unknown/exe
%System%\comp.exe
File name: %System%\comp.exeFile type: Executable File
Mime Type: unknown/exe
%System%\compact.exe
File name: %System%\compact.exeFile type: Executable File
Mime Type: unknown/exe
%System%\control.exe
File name: %System%\control.exeFile type: Executable File
Mime Type: unknown/exe
%System%\convert.exe
File name: %System%\convert.exeFile type: Executable File
Mime Type: unknown/exe
%System%\cacls.exe
File name: %System%\cacls.exeFile type: Executable File
Mime Type: unknown/exe
%System%\calc.exe
File name: %System%\calc.exeFile type: Executable File
Mime Type: unknown/exe
%System%\charmap.exe
File name: %System%\charmap.exeFile type: Executable File
Mime Type: unknown/exe
%System%\chkdsk.exe
File name: %System%\chkdsk.exeFile type: Executable File
Mime Type: unknown/exe
%System%\cmdl32.exe
File name: %System%\cmdl32.exeFile type: Executable File
Mime Type: unknown/exe
%System%\cmmon32.exe
File name: %System%\cmmon32.exeFile type: Executable File
Mime Type: unknown/exe
%System%\conime.exe
File name: %System%\conime.exeFile type: Executable File
Mime Type: unknown/exe
%System%\cscript.exe
File name: %System%\cscript.exeFile type: Executable File
Mime Type: unknown/exe
%System%\ctfmon.exe
File name: %System%\ctfmon.exeFile type: Executable File
Mime Type: unknown/exe
%System%\dcomcnfg.exe
File name: %System%\dcomcnfg.exeFile type: Executable File
Mime Type: unknown/exe
%System%\cmstp.exe
File name: %System%\cmstp.exeFile type: Executable File
Mime Type: unknown/exe
%System%\Com\comrepl.exe
File name: %System%\Com\comrepl.exeFile type: Executable File
Mime Type: unknown/exe
%System%\Com\comrereg.exe
File name: %System%\Com\comrereg.exeFile type: Executable File
Mime Type: unknown/exe
%System%\chkntfs.exe
File name: %System%\chkntfs.exeFile type: Executable File
Mime Type: unknown/exe
%System%\cidaemon.exe
File name: %System%\cidaemon.exeFile type: Executable File
Mime Type: unknown/exe
%System%\cipher.exe
File name: %System%\cipher.exeFile type: Executable File
Mime Type: unknown/exe
%System%\cisvc.exe
File name: %System%\cisvc.exeFile type: Executable File
Mime Type: unknown/exe
%System%\ckcnv.exe
File name: %System%\ckcnv.exeFile type: Executable File
Mime Type: unknown/exe
%System%\cleanmgr.exe
File name: %System%\cleanmgr.exeFile type: Executable File
Mime Type: unknown/exe
%System%\clean_all.exe
File name: %System%\clean_all.exeFile type: Executable File
Mime Type: unknown/exe
%System%\cliconfg.exe
File name: %System%\cliconfg.exeFile type: Executable File
Mime Type: unknown/exe
%System%\clipbrd.exe
File name: %System%\clipbrd.exeFile type: Executable File
Mime Type: unknown/exe
%System%\clipsrv.exe
File name: %System%\clipsrv.exeFile type: Executable File
Mime Type: unknown/exe
%System%\cmd.exe
File name: %System%\cmd.exeFile type: Executable File
Mime Type: unknown/exe
Registry Modifications
HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836} stubpath = "%ProgramFiles%\Bifrost\lol.exe s"HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost nck = ED 1B E6 27 B9 28 D6 32 74 C3 CD 74 FA 93 5B 67HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer UpdateHost = 00 50 5E 3F 95 96HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings ProxyEnable = 0x00000000HKEY_CURRENT_USER\Software\Bifrost klg = 00HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SOFTWARE\BifrostHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideoHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9D71D88C-C598-4935-C5D1-43AA4DB90836}HKEY_CURRENT_USER\Software\Bifrost
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.