Malware

Win32/Bifrose.ADR malicious file

Malware Removal

The Win32/Bifrose.ADR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Bifrose.ADR virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Win32/Bifrose.ADR?


File Info:

name: CF062DD69FD7F8A95AB9.mlw
path: /opt/CAPEv2/storage/binaries/26a2d632c5b1e5a7c555b24dfa1942ad9ba5df83562ca968b84c08bc68fe16ee
crc32: A7CD2463
md5: cf062dd69fd7f8a95ab91d24aa84bcaf
sha1: 0d050f277b944420fc00baf77fb3bfb1bc830ef0
sha256: 26a2d632c5b1e5a7c555b24dfa1942ad9ba5df83562ca968b84c08bc68fe16ee
sha512: a555082d5b27d89cb94d0a655f4c8a8ad72ad56477013dfaab74ee3cb8adf59f03c2af33d80c4cc03eda215da1d9cf2a00b8faa6faa7518e3b24e98cdee3c56f
ssdeep: 3072:+KJZx3+tGqTsnACpvmEhgwqvJ+Bsl94Fy+owCojmWsfby2oIukInqj96xeD:+KrxiyLvmWVXGlWowlynNVL5YW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DD14BF25F9C08132D1110A795C07D668A93E7B142E781187B7CE4B9D5EBB2861E3D3FB
sha3_384: 5b07db12589e91edcac9165597082ac595caf0c32546cfe613fb4113504c171ea77e1318502ea93304e4a0e93ab1c39e
ep_bytes: 558bec83c4f0b89c9a4100e8b8abfeff
timestamp: 1992-06-19 22:22:17

Version Info:

Comments:
CompanyName: Company
FileDescription: jewss 1.00 Installation
FileVersion: 1.00
LegalCopyright: Company
Translation: 0x0409 0x04e4

Win32/Bifrose.ADR also known as:

BkavW32.Common.B688362E
LionicTrojan.Win32.Bifrose.m!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Crypt.BH
FireEyeTrojan.Crypt.BH
CAT-QuickHealBackdoor.Bifrose.7730
SkyhighBehavesLike.Win32.Dropper.cc
McAfeeArtemis!CF062DD69FD7
Cylanceunsafe
SangforBackdoor.Win32.Bifrose.Vrwu
K7AntiVirusTrojan ( 000158851 )
AlibabaBackdoor:Win32/Bifrose.3f22ce5e
K7GWTrojan ( 004bff5e1 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaAI:Packer.16F2E3DC1F
SymantecTrojan Horse
ESET-NOD32Win32/Bifrose.ADR
APEXMalicious
KasperskyBackdoor.Win32.Bifrose.bgn
BitDefenderTrojan.Crypt.BH
NANO-AntivirusTrojan.Win32.Agent.cojafi
AvastWin32:Agent-AAZQ [Trj]
TencentWin32.Backdoor.Bifrose.Itgl
EmsisoftTrojan.Crypt.BH (B)
F-SecureBackdoor.BDS/Bifrose.keiqw
DrWebTrojan.Siggen2.42888
VIPRETrojan.Crypt.BH
TrendMicroTROJ_GEN.R03BC0DAT24
SophosTroj/Agent-JZZ
IkarusTrojan.Win32.Refroso
GDataTrojan.Crypt.BH
JiangminBackdoor.Bifrose.alg
GoogleDetected
AviraBDS/Bifrose.keiqw
VaristW32/Backdoor.HNRS-5187
Antiy-AVLTrojan/Win32.Bifrose.adr
Kingsoftmalware.kb.a.989
XcitiumMalware@#2u5o33km3y4lh
ArcabitTrojan.Crypt.BH
ZoneAlarmBackdoor.Win32.Bifrose.bgn
MicrosoftBackdoor:Win32/Bifrose.gen!C
CynetMalicious (score: 100)
VBA32Backdoor.Bifrose
ALYacTrojan.Crypt.BH
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DAT24
RisingBackdoor.Bifrose!1.A05C (CLASSIC)
YandexTrojan.Meredrop!c+0iR9j5ytM
MaxSecureTrojan.Malware.26224.susgen
AVGWin32:Agent-AAZQ [Trj]
Cybereasonmalicious.77b944
DeepInstinctMALICIOUS

How to remove Win32/Bifrose.ADR?

Win32/Bifrose.ADR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment