Backdoor

About “Backdoor:Win32/Bifrose” infection

Malware Removal

The Backdoor:Win32/Bifrose is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bifrose virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Bifrose?


File Info:

crc32: 49FB25FD
md5: 8c8ab79a453dbeeeba56cbee75f3e3fb
name: esg.dll
sha1: c55663697135d3fb7a5df263d38b9f25148ae2e1
sha256: 1d22b22a27af1c34b68140006d537f56670b603b596a88a66b2a5172a7e9d4e7
sha512: 44ccc35dfda5b5dcfb8f51abe097e11c745b359614f77aa75f1d4974cb412331be8dbb1ccc125b14f37272c5b0fe2fb91ee99125fef29764d26d31cffe19b6db
ssdeep: 24576:vdHy9xpf9A3FWJOhLcPNcVUOE+UC+TJ9Pur:vdmxB9AVWJOhmNcS/hw
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

Backdoor:Win32/Bifrose also known as:

MicroWorld-eScanGen:Variant.Barys.1607
McAfeeBackDoor-FACW!8C8AB79A453D
K7AntiVirusTrojan
NANO-AntivirusTrojan.Win32.Inject.mszcg
F-ProtW32/Bifrost.AD.gen!Eldorado
SymantecWS.Reputation.1
NormanW32/Bifrose.CRNB
TotalDefenseWin32/Bifrose.BND
TrendMicro-HouseCallTROJ_GEN.R47CDIS
AvastWin32:Malware-gen
BitDefenderGen:Variant.Barys.200
ViRobotBackdoor.Win32.A.Bancodor.1863896
EmsisoftBackdoor.Win32.Bifrose.AMN (A)
ComodoBackdoor.Win32.Agent.CFRW
F-SecureGen:Variant.Barys.200
VIPRETrojan.Win32.Generic!BT
AntiVirTR/Crypt.MWPM.Gen
TrendMicroTROJ_GEN.R47CDIS
McAfee-GW-EditionBackDoor-FACW!8C8AB79A453D
SophosTroj/SSonce-B
JiangminBackdoor/Bifrose.afwo
MicrosoftBackdoor:Win32/Bifrose
GDataGen:Variant.Barys.200
CommtouchW32/Bifrost.AD.gen!Eldorado
AhnLab-V3Trojan/Win32.Refroso
ESET-NOD32a variant of Win32/Packed.MoleboxVS.H
IkarusTrojan.Win32.Midgare
FortinetW32/Injector.DH!tr
AVGGeneric6_c.ARGK
PandaTrj/CI.A

How to remove Backdoor:Win32/Bifrose?

Backdoor:Win32/Bifrose removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment