Malware

About “Win32/Bifrose.NKY” infection

Malware Removal

The Win32/Bifrose.NKY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Bifrose.NKY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to disable UAC
  • Attempts to modify or disable Security Center warnings

How to determine Win32/Bifrose.NKY?


File Info:

name: 9BE417EF0EFCF46431E6.mlw
path: /opt/CAPEv2/storage/binaries/150aebaf1e05e771883afee960801a81b198bacb150c464190b57ef39135d8f4
crc32: 4593968B
md5: 9be417ef0efcf46431e6b36c011dd6ea
sha1: 2e791d6b54645825130609d57066724a852c4027
sha256: 150aebaf1e05e771883afee960801a81b198bacb150c464190b57ef39135d8f4
sha512: 49f426821a4d4e6dd256da85b7e540b52d5c0fb344dbd4ebf45699d61ab5b9aeca8e3bf7990f12861690c322f2e0dcb5f37fb1bbd3beb27992da12f0f918a873
ssdeep: 3072:hL/Y+7IyL0j6xd1D2WsCjbbGDxi5ok3Gr7:WYbrnSi5okS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B343B3A29BD5227D1B5C6B5CBD68837F010E87B34112D36A8C767598727D8368CB23E
sha3_384: 412378c449e22f4816b43f3ad1434d8ab738746007e90bf6e18be643c9aed89f4707c6b106f6d72087e514af226bc78d
ep_bytes: 682c174000e8eeffffff000000000000
timestamp: 2008-05-19 04:30:51

Version Info:

Translation: 0x0409 0x04b0
Comments: KqzzyCohoSffvyB
CompanyName: ZcqLNQhbEUnHb
FileDescription: kRjUZynkewtQmKQ
LegalCopyright: oftDmmZLnI
ProductName: JTpCpcDaY
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Stubexe
OriginalFilename: Stubexe.exe

Win32/Bifrose.NKY also known as:

MicroWorld-eScanGen:Heur.VB.Krypt.13
FireEyeGeneric.mg.9be417ef0efcf464
CAT-QuickHealTrojan.Vbinject.UG8
SkyhighBehavesLike.Win32.Infected.dt
ALYacGen:Heur.VB.Krypt.13
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Heur.VB.Krypt.13
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 0054ec131 )
BitDefenderGen:Heur.VB.Krypt.13
K7GWTrojan ( 0054ec131 )
BitDefenderThetaAI:Packer.B8C1FF5420
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Bifrose.NKY
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Dropper.Bifrost-7777327-0
KasperskyTrojan-Dropper.Win32.Injector.hthp
AlibabaTrojanDropper:Win32/Antivm.baba43d9
NANO-AntivirusTrojan.Win32.TrjGen.mcplz
RisingTrojan.AntiAV!1.647B (CLASSIC)
SophosTroj/VB-JHN
F-SecureTrojan.TR/Dropper.Gen
ZillyaDropper.Injector.Win32.83131
TrendMicroCryp_SpyEye
EmsisoftGen:Heur.VB.Krypt.13 (B)
IkarusTrojan.Win32.Zmunik
WebrootW32.Injector.Gen
VaristW32/VBInject.AC.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan[Dropper]/Win32.Injector
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Antivm.YD!MTB
XcitiumTrojWare.Win32.VB.GE@4pqh5b
ArcabitTrojan.VB.Krypt.13
ZoneAlarmTrojan-Dropper.Win32.Injector.hthp
GDataGen:Heur.VB.Krypt.13
GoogleDetected
AhnLab-V3Trojan/Win32.Xema.C12720
McAfeeGeneric VB.fo
DeepInstinctMALICIOUS
VBA32Malware-Cryptor.VB.gen.7
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallCryp_SpyEye
TencentWin32.Trojan-Dropper.Injector.Ljgl
YandexTrojan.VBInject.Gen.8
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bifrose.NKY!tr
AVGWin32:Inject-AII [Trj]
AvastWin32:Inject-AII [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Bifrose.NKY?

Win32/Bifrose.NKY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment