Backdoor

Backdoor:Win32/Bifrose.AE information

Malware Removal

The Backdoor:Win32/Bifrose.AE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bifrose.AE virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
badclik.no-ip.biz

How to determine Backdoor:Win32/Bifrose.AE?


File Info:

crc32: D99CD58B
md5: 146318d570c8462e5cff7e3b9a64cf08
name: tvsport.exe
sha1: 68d521cdd1a29c7f9913ebb41fc185a18cbe5614
sha256: 4ac093357979e218ff8a10bbe2ae250974443b505bf7ec729cf742c7397a5f46
sha512: 80bd07d6af5b0d4725e4a32da0ee0d4bb2ea2afbc901a4f136e10cb0dc9c5708c7a56d18f59601af2e898b2f081ddfdb8c2233fa4d4bf784977397c5198d3943
ssdeep: 3072:tT+V+fLt6ylc+pg7uLxg/29fQ/Ni6nfxQQuX2dU6mBlWHZT/oLiBMZN:UVQLT++q7B2q/3uX/4z0iB2
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Bifrose.AE also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Ulise.22594
FireEyeGeneric.mg.146318d570c8462e
CAT-QuickHealVirTool.DelfInject.AF
Qihoo-360Win32/Trojan.df0
McAfeeRDN/Generic BackDoor
CylanceUnsafe
AegisLabTrojan.Win32.Refroso.muCm
SangforMalware
K7AntiVirusTrojan ( 001788e91 )
BitDefenderGen:Variant.Ulise.22594
K7GWTrojan ( 001788e91 )
CrowdStrikewin/malicious_confidence_100% (W)
Invinceaheuristic
BitDefenderThetaAI:Packer.61A971811D
F-ProtW32/VBInject.V.gen!Eldorado
SymantecBackdoor.Bifrose!gen
TotalDefenseWin32/Bifrose.ZG!genus
TrendMicro-HouseCallTROJ_BREDLAB.SMD
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-36155
GDataGen:Variant.Ulise.22594
KasperskyBackdoor.Win32.Bifrose.fxv
AlibabaBackdoor:Win32/Bifrose.9360a327
NANO-AntivirusTrojan.Win32.Dybalom.dvxne
APEXMalicious
TencentWin32.Backdoor.Bifrose.Dwtf
Ad-AwareGen:Trojan.Heur.PM.2
SophosMal/BigMole-B
ComodoMalware@#1w0dwmsdjotfp
F-SecureTrojan:W32/Agent.DQKQ
DrWebBackDoor.Bifrost.20804
ZillyaBackdoor.Bifrose.Win32.66250
TrendMicroTROJ_BREDLAB.SMD
McAfee-GW-EditionBehavesLike.Win32.RAHack.cc
Trapminemalicious.high.ml.score
CMCTrojan.Win32.Refroso.1!O
EmsisoftGen:Variant.Ulise.22594 (B)
SentinelOneDFI – Malicious PE
CyrenW32/VBInject.V.gen!Eldorado
JiangminTrojan.Generic.bjusv
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Refroso.a
Endgamemalicious (high confidence)
ArcabitTrojan.Ulise.D5842
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Bifrose.AE
Acronissuspicious
VBA32BScope.Backdoor.Agent
ALYacGen:Variant.Ulise.22594
PandaGeneric Malware
ESET-NOD32a variant of Win32/Packed.MoleboxUltra suspicious
RisingBackdoor.Bifrose!8.B24 (CLOUD)
YandexTrojan.Refroso.Gen.3
IkarusTrojan.Win32.Agent
FortinetW32/Refroso.BKBI!tr
AVGWin32:Malware-gen
Cybereasonmalicious.570c84
Paloaltogeneric.ml
MaxSecurePacked.Rebhip.a

How to remove Backdoor:Win32/Bifrose.AE?

Backdoor:Win32/Bifrose.AE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment