TR/Agent.bicf Virus Removal

TR/Agent.bicf is a virus that was written in MS Visual C++ and it propogates through network drives is also called Kaspersky: Trojan.Win32.Agent.bicf

Type of Infection : Trojan ||    Risk Level : Medium

Behaviour of TR/Agent.bicf virus
• Registry modification

Path:

  • %WINDIR%\security\lsass.exe
  • %drive%\viewfiles.exe

Registry Entries of this trojan virus

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
• “Windows Intranet controller”=”"%WINDIR%\security\lsass.exe”"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
• “Windows Intranet controller”=”%WINDIR%\security\lsass.exe”

Network access

lamers.c0re.us:65501