Backdoor

Backdoor:Win32/Bifrose.BH removal instruction

Malware Removal

The Backdoor:Win32/Bifrose.BH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bifrose.BH virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Starts servers listening on 0.0.0.0:666
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

Related domains:

web.icq.com

How to determine Backdoor:Win32/Bifrose.BH?


File Info:

crc32: D481EED1
md5: 40cfb6a56b34b66841b1fc24990bf8d0
name: 40CFB6A56B34B66841B1FC24990BF8D0.mlw
sha1: eea1ad96443a58d8ce69b0cf48f6615b3fee6090
sha256: a2d32bc8f81ef5ad6f5dfb2d442efcaa8e280549d8f31bb0d04ef0444d50c0a3
sha512: b93513a24cf9fab2a06656ea6196acbb1f0f390baaa80d43892ed821fd7ba609560823a04dc61bff54986c35f6cff622698d9e390047a9caa0e7f09477032411
ssdeep: 1536:x/k/EdxikMK0QVrPtRGh7w/5j4TWGM+/AFNh5VX+oa+L:x/FdX0QVrt45wxjuWU/In5VuJ+L
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Bifrose.BH also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop.444
CynetMalicious (score: 100)
CMCGeneric.Win32.40cfb6a56b!MD
CAT-QuickHealTrojan.Generic
ALYacDropped:Backdoor.Generic.192434
CylanceUnsafe
ZillyaDropper.Joiner.Win32.187
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanDropper:Win32/Joiner.b97a287c
Cybereasonmalicious.56b34b
CyrenW32/Backdoor.FDZM-6980
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDropper.Small.O
APEXMalicious
AvastWin32:AlLight [Trj]
ClamAVWin.Trojan.BeastDoor-1
KasperskyTrojan-Dropper.Win32.Joiner.bk
BitDefenderDropped:Backdoor.Generic.192434
NANO-AntivirusTrojan.Win32.Joiner.bwvewu
MicroWorld-eScanDropped:Backdoor.Generic.192434
TencentWin32.Trojan-dropper.Joiner.Pcjf
Ad-AwareDropped:Backdoor.Generic.192434
SophosMal/Generic-R + Troj/Mdrop-CH
ComodoTrojWare.Win32.TrojanDropper.Joiner.K@12v2f7
BitDefenderThetaAI:Packer.C9B420B923
TrendMicroBKDR_BIFROSE.ES
McAfee-GW-EditionBehavesLike.Win32.VirRansom.mc
FireEyeGeneric.mg.40cfb6a56b34b668
EmsisoftDropped:Backdoor.Generic.192434 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Bifrose.bfh
WebrootW32.Bifrose.Gen
AviraBDS/BeastDoor.192.A
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.E8C6C8
KingsoftWin32.Troj.Joiner.bk.(kcloud)
MicrosoftBackdoor:Win32/Bifrose.BH
ArcabitBackdoor.Generic.D2EFB2
AegisLabTrojan.Win32.Joiner.b!c
ZoneAlarmTrojan-Dropper.Win32.Joiner.bk
GDataDropped:Backdoor.Generic.192434
AhnLab-V3Trojan/Win32.Bifrose.C311
McAfeeMultiDropper-CE
MAXmalware (ai score=100)
VBA32BScope.TrojanDropper.Small
MalwarebytesMalware.AI.3258268543
PandaBck/Bifrose.AV
TrendMicro-HouseCallBKDR_BIFROSE.ES
RisingDropper.Freeline (CLOUD)
YandexTrojan.GenAsa!VXDlq/l/x1Q
IkarusBackdoor.Win32.Bifrose
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Mdrop.CH!tr
AVGWin32:AlLight [Trj]
Paloaltogeneric.ml

How to remove Backdoor:Win32/Bifrose.BH?

Backdoor:Win32/Bifrose.BH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment