Backdoor

About “Backdoor:Win32/Bifrose!pz” infection

Malware Removal

The Backdoor:Win32/Bifrose!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bifrose!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Bifrose!pz?


File Info:

name: 75536BF5374B9887E343.mlw
path: /opt/CAPEv2/storage/binaries/ed65384904f21f0f2bbc681b78c9177997998df8548ee1fd6b5a9a3d676e012d
crc32: 096157FE
md5: 75536bf5374b9887e343a120bd853900
sha1: 2f4297a0b6216e9d137dcd9819a6c28474cba21d
sha256: ed65384904f21f0f2bbc681b78c9177997998df8548ee1fd6b5a9a3d676e012d
sha512: ef00c9314dcd6e395f3b1a368d886bd5837d30fbc3ca6216d102cbd60f626ad1f7abbfe7d8ffa2ce36fe6887b1354ddd2e7377a75b0eb74d66dbecb732ee84a1
ssdeep: 24576:OVcvpec5e0mZf9LoaeHfIXF6wb94S/CoohD3m:OVcvpec5e0mZfre/fwbe4CoohD3m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11665AE113FCAC07BC26E117209669726A2A7BD156B3456C72BA13F5DAF342C2BC3E705
sha3_384: 0cfe325d5d817026655e22b608869792d5817e0e636bbdd48e5a8d9bd5755d306dd5d0b5c93671d028c5447cf4449f67
ep_bytes: 6a606860024b00e88b0400008365fc00
timestamp: 2007-12-28 15:29:15

Version Info:

FileDescription: HilEx Bifrost Privet Version
FileVersion: 1, 2, 1, 0
InternalName: HilEx Bifrost
OriginalFilename: Bifrost.exe
ProductName: HilEx Bifrost
ProductVersion: 1, 2, 1, 0
Translation: 0x0409 0x04b0

Backdoor:Win32/Bifrose!pz also known as:

LionicHacktool.Win32.Bifrose.kYZ3
MicroWorld-eScanGeneric.Bifrose.7C41C98B
FireEyeGeneric.mg.75536bf5374b9887
SkyhighBehavesLike.Win32.Injector.th
McAfeeBackDoor-CEP.gen.au
MalwarebytesGeneric.Malware.AI.DDS
VIPREGeneric.Bifrose.7C41C98B
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 005325cc1 )
K7AntiVirusTrojan ( 005325cc1 )
BaiduWin32.Trojan.Bifrose.c
VirITTrojan.Win32.Constructor.EDW
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Bifrose.NTC
APEXMalicious
TrendMicro-HouseCallTROJ_BIFROSE_000000d.TOMA
ClamAVWin.Trojan.Bifrose-15615
KasperskyBackdoor.Win32.Bifrose.acci
BitDefenderGeneric.Bifrose.7C41C98B
NANO-AntivirusTrojan.Win32.Fakealert.flfama
SUPERAntiSpywareHeur.Agent/Gen-Bifrost
AvastWin32:PUP-gen [PUP]
TencentMalware.Win32.Gencirc.10b34c78
EmsisoftGeneric.Bifrose.7C41C98B (B)
GoogleDetected
F-SecureTrojan.TR/Bifrose.Const.B
DrWebTrojan.Fakealert.25680
ZillyaBackdoor.BifroseGenS.Win32.2
TrendMicroTROJ_BIFROSE_000000d.TOMA
Trapminemalicious.high.ml.score
SophosMal/Bifrose-S
SentinelOneStatic AI – Malicious PE
JiangminConstructor.Bifrose.lj
VaristW32/Bifrost.A.gen!Eldorado
AviraTR/Bifrose.Const.B
MAXmalware (ai score=100)
Antiy-AVLHackTool[Constructor]/Win32.Bifrose
KingsoftWin32.Hack.Bifrose.acci
MicrosoftBackdoor:Win32/Bifrose!pz
XcitiumConstructor.Win32.Bifrose.~R@1lyib
ArcabitGeneric.Bifrose.7C41C98B
ViRobotBackdoor.Win32.Bifrose.1466368
ZoneAlarmBackdoor.Win32.Bifrose.acci
GDataGeneric.Bifrose.7C41C98B
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Bifrose.R3641
BitDefenderThetaAI:Packer.A105DD1F20
ALYacGeneric.Bifrose.7C41C98B
TACHYONConstructor/W32.Bifrose.1466368.B
VBA32Trojan.FakeAlert
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.KillAV!1.9942 (CLASSIC)
IkarusConstructor.Win32.Bifrose
FortinetMalware_fam.A
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.5374b9
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Bifrose.NTC

How to remove Backdoor:Win32/Bifrose!pz?

Backdoor:Win32/Bifrose!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment