Threat Search: 

ThreatExpert's Statistics for Backdoor.Bifrost [Ikarus]:

Backdoor.Bifrost [Ikarus] is also known as:
Threat AliasNumber of Incidents
Backdoor:Win32/Bifrose.ACI [Microsoft]41
BackDoor-CEP.svr [McAfee]40
Infostealer [Symantec]40
BKDR_BIFROSE.MIC [Trend Micro]38
Backdoor.Win32.Bifrose.fny [Kaspersky Lab]29
Dropper/Agent.29565 [AhnLab]29
Mal/Bifrose-R, Mal/Bifrose-E [Sophos]27
Mal/Bifrose-E [Sophos]14
Backdoor.Win32.Bifrose.ahyc [Kaspersky Lab]4
Backdoor.Bifrose!sd6 [PC Tools]3
Backdoor.Trojan [Symantec]3
Packed.Win32.Krap.c [Kaspersky Lab]3
Trojan Horse [Symantec]3
Win-Trojan/Krap.30844 [AhnLab]3
Backdoor:Win32/Bifrose.FO [Microsoft]2
New Win32 [McAfee]2
Virus.Win32.Sality.aa [Kaspersky Lab]2
Backdoor.Bifrose [Symantec]1
Backdoor.Bifrose!ct [PC Tools]1
Backdoor.Win32.Bifrose.adcr [Kaspersky Lab]1
Backdoor.Win32.Bifrose.ancu [Kaspersky Lab]1
Backdoor.Win32.Bifrose.aoxj [Kaspersky Lab]1
Backdoor:Win32/Bifrose [Microsoft]1
Backdoor-CEP [McAfee]1
BackDoor-CEP [McAfee]1
Mal/Bifrose-R [Sophos]1
Mal/Bifrose-R, Mal/Bifrose-E, W32/Scribble-B [Sophos]1
Mal/Bifrose-R, Mal/Bifrose-S [Sophos]1
Mal/Generic-A [Sophos]1
Mal/Sality-B [Sophos]1
Mal/UnkPack-Fam [Sophos]1
Packed.Win32.Black.a [Kaspersky Lab]1
PE_SALITY.BU [Trend Micro]1
PE_VIRUX.H-3 [Trend Micro]1
Trojan.Win32.Midgare.gga [Kaspersky Lab]1
Trojan.Win32.MustHave.a [Kaspersky Lab]1
Trojan-GameThief.Win32.Nilage.dqq [Kaspersky Lab]1
Trojan-PSW.Generic [PC Tools]1
Virus.Win32.Virut.ce [Kaspersky Lab]1
Virus:Win32/Sality.AM [Microsoft]1
Virus:Win32/Virut.BM [Microsoft]1
W32.Virut.CF [Symantec]1
Win32/Virut.F [AhnLab]1
Win-Trojan/Bifrose.1236408 [AhnLab]1
Win-Trojan/Midgare.572439 [AhnLab]1

Backdoor.Bifrost [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Sweden39
Saudi Arabia2
Russian Federation1

Backdoor.Bifrost [Ikarus] is known to be created as:
%AppData%\server.exe
%LocalSettings%\tempservices.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\mms\msnmsgr.exe
%System%\bifrost\server.exe
%System%\lncom_.exe
%System%\sex\server.exe
%System%\system32\server.exe
%System%\updat\updat.exe
%Temp%\bif1.exe
%Temp%\ixp000.tmp\server.exe
%Temp%\svchost1.exe.exe
%Temp%\tempfile.exe
%Windir%\pipodrag\msnmsgr.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %LocalSettings% is a variable that specifies the current user's local settings folder. By default, this is C:\Documents and Settings\[UserName]\Local Settings (Windows NT/2000/XP).
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.