The server component (29,053 bytes) is dropped to C:\Program Files\Bifrost\server.exe with default settings and, when running, connects to a predefined IP address on TCP port 81, awaiting commands from the remote

uStart Page = hxxp://www.google.co.uk/ uWindow Title = Internet Explorer, optimized for Bing and MSN BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common

Press OK7. This item may not be safe to have on your system. A text file will open in your default text editor.Please copy and paste the Scan Log results in your next reply.Click Close to exit the program.-- If you have a problem Click the Start button to begin the cleaning process and let it run uninterrupted to completion.TFC will clear out all temp folders for all user accounts (temp, IE temp, Java, FF,

Locate and uncheck Hide file extensions for known file types. Then paste contents into your next reply.RE-Enable your antivirus program.Copy & Paste contents of Log.txt & Info.txt & Checkup.txt & log from Bitdefender.Use separate replies as needed if logs do not

C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Common

Summary: Trojan.Agent/Gen-Bifrose.Process Company: Unknown Description: Trojan that may log user information and possibly block access to certain security related sites. Most of the page is covered over by a gray box; see attached png image file of browser page.

BIFROSE.TRACE Started by rick_niec , Feb 25 2012 11:00 AM