Backdoor

Backdoor:Win32/Bifrose!pz removal guide

Malware Removal

The Backdoor:Win32/Bifrose!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bifrose!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Backdoor:Win32/Bifrose!pz?


File Info:

name: 067DC1FDF0F6680B8BA2.mlw
path: /opt/CAPEv2/storage/binaries/2184c99b50d0bf900f8b35c958db1ef857598dbee1beba9f4ab4636447b9b3b5
crc32: A77B4E04
md5: 067dc1fdf0f6680b8ba29e921c216931
sha1: 5c0ddf2013c9b49e803d7f098d15f706f38887ea
sha256: 2184c99b50d0bf900f8b35c958db1ef857598dbee1beba9f4ab4636447b9b3b5
sha512: 76507cdf24accc5e69405138e81914ab1e4f6297409d0e3c4be1f30fe1850b9a4aa54b768699755fea6f3207aeacb39d24734c1cb96ef96765382524e13b363a
ssdeep: 1536:OpXh9PIep8NPkrB0+KH5bHnIQhqRh2HgB1SgXSHd5lfSw62k/G0G+owkRsUKf:+hdLp2Mrc5bH1SIgB+HXgwHhwkBe
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T16534B003BA68C034E15445B85C7A7B73D9BE7900079A52E7C3D8DAE4DDF4A606A0B72F
sha3_384: 9f8b28badd30a042467f3436a921be2e5833049678caf91a4fec832b5b3a525987fe6ea6bc0b306922e9ed350e492d92
ep_bytes: eb1066623a432b2b484f4f4b90e9f840
timestamp: 2010-09-21 16:50:59

Version Info:

0: [No Data]

Backdoor:Win32/Bifrose!pz also known as:

BkavW32.Common.33BBBD5B
LionicTrojan.Win32.KillAV.4!c
MicroWorld-eScanGen:Variant.Barys.67671
ClamAVWin.Trojan.Agent-334483
FireEyeGeneric.mg.067dc1fdf0f6680b
CAT-QuickHealTrojan.GenericPMF.S27590417
SkyhighBehavesLike.Win32.PUPXVK.dz
McAfeeObfuscated-FIO!hb
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Wansrog.Win32.12
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Wansrog.e075817b
K7GWTrojan ( 004d03be1 )
K7AntiVirusTrojan ( 004d03be1 )
VirITTrojan.Win32.Agent3.BRGL
SymantecTrojan.KillAV
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Wansrog.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Barys.67671
NANO-AntivirusTrojan.Win32.MLW.cortv
AvastWin32:KillAV-AJD [Trj]
TencentMalware.Win32.Gencirc.10b3b513
EmsisoftGen:Variant.Barys.67671 (B)
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.Siggen2.26898
VIPREGen:Variant.Barys.67671
TrendMicroTROJ_KILLAV.SMJF
SophosMal/Agent-FW
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.67671
JiangminTrojan/Genome.ansa
WebrootW32.Trojan.Agent
GoogleDetected
AviraTR/ATRAPS.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.Wansrog.ABS@4piqq6
ArcabitTrojan.Barys.D10857
ViRobotTrojan.Win32.A.Zapchast.241672.C
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Bifrose!pz
VaristW32/KillAV.AW.gen!Eldorado
AhnLab-V3Trojan/Win32.QQPass.R1855
BitDefenderThetaGen:NN.ZedlaF.36744.oC5@aW!Xoff
ALYacGen:Variant.Barys.67671
VBA32BScope.Trojan.Agent
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_KILLAV.SMJF
RisingTrojan.Agent!8.B1E (TFE:6:It7wrCjdBdD)
YandexTrojan.GenAsa!Z5oRU3gTFvs
IkarusTrojan.Win32.Sisron
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/Generic.AC.24d16!tr
AVGWin32:KillAV-AJD [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Bifrose!pz?

Backdoor:Win32/Bifrose!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment