Trojan

Trojan:Win32/Bifrose!pz removal tips

Malware Removal

The Trojan:Win32/Bifrose!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Bifrose!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine Trojan:Win32/Bifrose!pz?


File Info:

name: 3A78C4C774268D19FF09.mlw
path: /opt/CAPEv2/storage/binaries/ea295b5ab6550ac28789353bc707de380990ce868d36a459512a60b517f0f9ac
crc32: 0DDAD588
md5: 3a78c4c774268d19ff0947abeb2e078b
sha1: ef6db3da0548df8a3f135f74b459c0641a38cb35
sha256: ea295b5ab6550ac28789353bc707de380990ce868d36a459512a60b517f0f9ac
sha512: b319cc2f0569ba819b0045b76859b1e755e4af71365c4c105740e7231f8f1f76e1172458ab06d253b48f8c7cf53ac3d4dbf3fa1429720256792b78902d1de3bd
ssdeep: 3072:6KloQSrkKgRENEI5apGTwQqVMTW0hiJDea8ky:E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12FE35F1966FFB9CAE100B9F2DFD2D1B99657D1340E0B30BB214451DB0B2AC2667EB5B0
sha3_384: e81d2389046abda4eb7fa7b499261c33ad5f11c056c3cc5c1713d7941739b320fcd2a774ee26dd1e8143080762a8feef
ep_bytes: 6814124000e8f0ffffff000000000000
timestamp: 2011-03-27 08:02:14

Version Info:

Translation: 0x0409 0x04b0
Comments: twoMcUEnp
CompanyName: tyUcjNba
FileDescription: CHPFlu
LegalCopyright: GuEcQAB
ProductName: uSkKkvqHrNxIO
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Stub5
OriginalFilename: Stub5.exe

Trojan:Win32/Bifrose!pz also known as:

BkavW32.AIDetectMalware
AVGWin32:Bifrose-ESN [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop3.39680
MicroWorld-eScanGen:Heur.VB.Krypt.13
FireEyeGeneric.mg.3a78c4c774268d19
CAT-QuickHealTrojan.VB.Gen
SkyhighBehavesLike.Win32.Generic.cz
McAfeeArtemis!3A78C4C77426
MalwarebytesMalware.AI.1543672429
ZillyaBackdoor.Bifrose.Win32.94928
SangforSuspicious.Win32.Save.vb
K7AntiVirusRiskware ( 0015e4f11 )
AlibabaTrojanDropper:Win32/Bifrose.8b5d3979
K7GWRiskware ( 0015e4f11 )
BitDefenderThetaAI:Packer.C3CBF58D1F
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.DQZ
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Malware.Refroso-6939073-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.VB.Krypt.13
NANO-AntivirusTrojan.Win32.VB.kjwnkl
AvastWin32:Bifrose-ESN [Trj]
TencentWin32.Trojan.Generic.Bwnw
EmsisoftGen:Heur.VB.Krypt.13 (B)
F-SecureTrojan:W32/VBinject.Y
VIPREGen:Heur.VB.Krypt.13
TrendMicroTROJ_BIFROS.SMI
Trapminemalicious.moderate.ml.score
SophosMal/Generic-G
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Injector
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojan:Win32/Bifrose!pz
XcitiumBackdoor.Win32.Bifrost.CA@2o9qqu
ArcabitTrojan.VB.Krypt.13
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Heur.VB.Krypt.13
VaristW32/Bifrost.Y.gen!Eldorado
AhnLab-V3Backdoor/Win32.Bifrose.C5245
VBA32SScope.Trojan.VBRA.2331
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_BIFROS.SMI
RisingHackTool.VBInject!8.1A0 (TFE:5:8Q8bSaBseBC)
IkarusGen.Heur
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/VBObfus.C!tr
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Krypt

How to remove Trojan:Win32/Bifrose!pz?

Trojan:Win32/Bifrose!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment