Malware

About “Win32/Bifrose.NIO” infection

Malware Removal

The Win32/Bifrose.NIO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Bifrose.NIO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Win32/Bifrose.NIO?


File Info:

name: 8436EA4FD39713575CDC.mlw
path: /opt/CAPEv2/storage/binaries/16c33a3e49e96f79b28d4426980ee9330cb79895023c44b856c4088f6b288ed4
crc32: 30692C13
md5: 8436ea4fd39713575cdc29d9a7422477
sha1: 2979088d11eb365b2f0a76cf4f97cc361acdb225
sha256: 16c33a3e49e96f79b28d4426980ee9330cb79895023c44b856c4088f6b288ed4
sha512: 90c5a91af9a996f50014f0df2b100805d1130ac0853bb3397618f3a167e31af8a7152dad608223717cb44fdbd291022404f99a92cf87c854f6a570b7d369cad6
ssdeep: 1536:/MJ249icel/Z01/NBX4UDpegM3zwACUJGLq42GrElP2T/1oHd5RVJ6sYTCFi10IN:UX0e1FB/DpKjCLHcYT4i10ImEM3Yr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T101443E3A19BD123BD1A4CAB5CFC68827F454E47B34212D36A8D787998347D8369CB13E
sha3_384: 8d8caf5d90d4124a05c8e0b3730413ba5e2a5d704a5fffc78e7fad9d863d0b4abd4038f65300e1f8a6a18ab4e13b528c
ep_bytes: 6844164000e8f0ffffff000000000000
timestamp: 2012-03-03 18:23:02

Version Info:

Translation: 0x0409 0x04b0
Comments: gvNiBvlQaaZ
CompanyName: zCQmoxH
FileDescription: aNKEQUrMlr
LegalCopyright: PGTeMMAmNkwKsJv
ProductName: VZcTsHAlSUp
FileVersion: 1.00
ProductVersion: 1.00
InternalName: 3
OriginalFilename: 3.exe

Win32/Bifrose.NIO also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Trojan.Heur.ZGY.7
ClamAVWin.Dropper.Bifrost-7777327-0
FireEyeGeneric.mg.8436ea4fd3971357
CAT-QuickHealTrojan.Vbinject.UG8
SkyhighGeneric VB.fl
ALYacGen:Trojan.Heur.ZGY.7
Cylanceunsafe
ZillyaTrojan.Bifrose.Win32.21468
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0054ec131 )
AlibabaTrojan:Win32/Refroso.50267928
K7GWTrojan ( 0054ec131 )
Cybereasonmalicious.d11eb3
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Bifrose.NIO
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Refroso.hphs
BitDefenderGen:Trojan.Heur.ZGY.7
NANO-AntivirusTrojan.Win32.VB.tzasq
SUPERAntiSpywareTrojan.Agent/Gen-Falleg[Cont]
AvastWin32:Inject-AII [Trj]
TencentWin32.Trojan.Refroso.Mjgl
SophosTroj/VB-JHN
F-SecureBackdoor.BDS/Bifrose.OB
VIPREGen:Trojan.Heur.ZGY.7
TrendMicroCryp_SpyEye
EmsisoftGen:Trojan.Heur.ZGY.7 (B)
IkarusTrojan.Win32.Refroso
GDataGen:Trojan.Heur.ZGY.7
WebrootW32.Malware.Gen
GoogleDetected
AviraBDS/Bifrose.OB
Antiy-AVLTrojan/Win32.Nvert
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Refroso.CTS@4l2cok
ArcabitTrojan.Heur.ZGY.7
ZoneAlarmTrojan.Win32.Refroso.hphs
MicrosoftVirTool:Win32/VBInject.UG
VaristW32/VBInject.AC.gen!Eldorado
AhnLab-V3Trojan/Win32.Refroso.R30043
McAfeeGeneric VB.fl
MAXmalware (ai score=100)
VBA32Malware-Cryptor.VB.gen.7
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallCryp_SpyEye
RisingHackTool.VBInject!1.6497 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Bifrose.NKY!tr
BitDefenderThetaAI:Packer.CB444DC315
AVGWin32:Inject-AII [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Bifrose.NIO?

Win32/Bifrose.NIO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment