Malware

How to remove “Win32/Bifrose.ADR”?

Malware Removal

The Win32/Bifrose.ADR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Bifrose.ADR virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Bifrose.ADR?


File Info:

name: 8CBCD25EAEEAC3029807.mlw
path: /opt/CAPEv2/storage/binaries/a490d02b01960a8147525b9814411d18700a58d19b3fbd07868a99cf9cfd07f2
crc32: 2D4B3B85
md5: 8cbcd25eaeeac3029807b62043e126b5
sha1: 54291a5809391da258c96c402f0789aba6bfe5c6
sha256: a490d02b01960a8147525b9814411d18700a58d19b3fbd07868a99cf9cfd07f2
sha512: 3913dad1064d43e2e64175398d6ca5ab94852c29c528fc06443a154b10224120abbf8a71a1b6c26633dd34546e8253de68bb05aaf93ecfb31b92a2ac57ecdc71
ssdeep: 384:6mOyMLjKMPH1Dxw7ZA8l9ZoA7k+w9G5hmssR0IkR46nzojn8mgRRtssIeo/r5J1f:rUjKVjl9xw3x6nz7vj1wrHfKs+wP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C43D08EA720FD62C1EF17398AFE56FD4A66A84041926B231352CBDC2EF4592343B459
sha3_384: 21c33ff91c906838d764b30ca9f607a4cc9db76acf278eb2c28ad5cc9fc3cc7048b17c9d2b7a1d4863bfdebdbe8e934d
ep_bytes: 558bec83ec4456ff15101040008bf08a
timestamp: 2007-01-17 22:19:02

Version Info:

0: [No Data]

Win32/Bifrose.ADR also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.li2k
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Crypt.BH
ClamAVWin.Trojan.Agent-36385
FireEyeGeneric.mg.8cbcd25eaeeac302
CAT-QuickHealBackdoor.Bifrose.7730
SkyhighBehavesLike.Win32.Backdoor.qm
McAfeeBackDoor-CEP.w
MalwarebytesGeneric.Malware.AI.DDS
ZillyaBackdoor.Bifrose.Win32.41900
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/Bifrose.c3bbedb1
K7GWTrojan ( 000158851 )
K7AntiVirusTrojan ( 000158851 )
ArcabitTrojan.Crypt.BH
BaiduWin32.Trojan.Agent.dm
VirITBackdoor.Win32.Small.AA
SymantecTrojan Horse
ESET-NOD32Win32/Bifrose.ADR
ZonerTrojan.Win32.22108
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Bifrose.fba
BitDefenderTrojan.Crypt.BH
NANO-AntivirusTrojan.Win32.Agent.cojafi
AvastWin32:Agent-AAZQ [Trj]
TencentTrojan.Win32.Agent.bcn
TACHYONBackdoor/W32.Bifrose.57344.BE
EmsisoftTrojan.Crypt.BH (B)
F-SecureBackdoor.BDS/Bifrose.zwz
DrWebBackDoor.Bifrost.834
VIPRETrojan.Crypt.BH
TrendMicroBKDR_BIFROSE.MIC
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusVirus.Win32.Bifrose
JiangminBackdoor/Bifrose.ks
WebrootW32.Malware.Gen
GoogleDetected
AviraBDS/Bifrose.zwz
Antiy-AVLTrojan/Win32.Bifrose.adr
KingsoftWin32.Hack.Bifrose.73757
XcitiumBackdoor.Win32.Bifrose.ADR@3xn7
MicrosoftBackdoor:Win32/Bifrose
ViRobotTrojan.Win32.A.Agent.28672.BV
ZoneAlarmBackdoor.Win32.Bifrose.fba
GDataWin32.Trojan.PSE.N540AG
VaristW32/Bifrost.E.gen!Eldorado
AhnLab-V3Trojan/Win32.Bifrose.R6587
Acronissuspicious
VBA32Backdoor.Bifrose
ALYacTrojan.Crypt.BH
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallBKDR_BIFROSE.MIC
RisingBackdoor.Bifrose!1.A05C (CLASSIC)
YandexTrojan.GenAsa!HgSSZWe0hGI
SentinelOneStatic AI – Malicious PE
MaxSecurePoly.Trojan.Agent.BCN
FortinetW32/Bifrose.BBT!tr
BitDefenderThetaGen:NN.ZexaF.36744.diX@aKKDXQfG
AVGWin32:Agent-AAZQ [Trj]
DeepInstinctMALICIOUS

How to remove Win32/Bifrose.ADR?

Win32/Bifrose.ADR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment