Threat Search: 

ThreatExpert's Statistics for Virus.Win32.Bifrose [Ikarus]:

Virus.Win32.Bifrose [Ikarus] is also known as:
Threat AliasNumber of Incidents
Constructor.Win32.Bifrose.j [Kaspersky Lab]538
Backdoor.Bifrose [Symantec]472
Constructor/Bifrose.1466368 [AhnLab]462
BackDoor-CEP.svr [McAfee]363
Trojan.Win32.Agent.bcn [Kaspersky Lab]349
Mal/Bifrose-S [Sophos]331
Backdoor:Win32/Bifrose.ACI [Microsoft]313
Trojan Horse [Symantec]263
Constructor:Win32/Bifrose.A [Microsoft]254
Win-Trojan/Bifrose.29053 [AhnLab]242
Backdoor.Bifrose [PC Tools]205
BKDR_BIFROSE.AFU [Trend Micro]201
Constructor.Bifrose!sd6 [PC Tools]179
BKDR_BIFROSE.MIC [Trend Micro]142
Mal/Bifrose-R, Mal/Bifrose-G, Mal/Bifrose-D, Mal/Bifrose-A, Mal/Bifrose-E [Sophos]141
BKDR_AHZE.NY [Trend Micro]137
BackDoor-CEP.gen.au [McAfee]128
Trojan:Win32/Midgare.A [Microsoft]127
Backdoor:Win32/Bifrose.gen!B [Microsoft]123
Backdoor.Bifrose!sd6 [PC Tools]107
Mal/Bifrose-G, Mal/Bifrose-D, Mal/Bifrose-A, Mal/Bifrose-E [Sophos]105
Infostealer [Symantec]103
Trojan.Agent.CZZK [PC Tools]96
Backdoor:Win32/Bifrose [Microsoft]92
Mal/Generic-A [Sophos]89
Virus.Win32.Virut.ce [Kaspersky Lab]67
Win32/Virut.F [AhnLab]66
BackDoor-CEP.gen.a [McAfee]61
Mal/EncPk-FH [Sophos]61
W32.Virut.CF [Symantec]60
Backdoor.Trojan [Symantec]57
Virus:Win32/Virut.BM [Microsoft]54
Troj/Agent-JZZ [Sophos]53
BackDoor-CEP.gen.g [McAfee]46
W32/Virut.n.gen [McAfee]46
Backdoor:Win32/Bifrose.gen!C [Microsoft]43
Mal/Bifrose-S, W32/Scribble-B [Sophos]42
Win-Trojan/Midgare.30208 [AhnLab]41
Virus:Win32/Sality.AM [Microsoft]40
W32.Sality.AE [Symantec]40
W32/Sality-AM [Sophos]38
Trojan.Agent.ECMZ [PC Tools]36
Backdoor.Win32.Bifrose.aosq [Kaspersky Lab]35
BKDR_BIFROSE.BQL [Trend Micro]34
Backdoor.Bifrose.AHY [PC Tools]33
Mal/UnkPack-Fam [Sophos]31
Trojan.Win32.Monder.ybg [Kaspersky Lab]30
Win-Trojan/Bifrose.1441792 [AhnLab]30
Mal/Bifrose-S, Mal/Bifrose-S [Sophos]29
TROJ_AGENT.AGY [Trend Micro]28
Trojan.Midgare.hhn [PC Tools]27
W32/Scribble-B [Sophos]25
Backdoor.Win32.Bifrose.fmv [Kaspersky Lab]24
Constructor.Win32.Bifrose.gy [Kaspersky Lab]24
W32/Sality.gen [McAfee]24
Backdoor.Win32.Bifrose.aleu [Kaspersky Lab]23
Mal/Generic-E, Mal/Bifrose-S [Sophos]23
Troj/Agent-HBG [Sophos]23
Troj/AgentU-Fam [Sophos]22
Backdoor:Win32/Bifrose.EY [Microsoft]21
Constructor.Win32.Bifrose.be [Kaspersky Lab]21
Mal/Generic-E, Mal/Bifrose-S, Mal/Bifrose-S [Sophos]21
Trojan.Win32.Midgare.ebu [Kaspersky Lab]19
Virus:Win32/Sality.G [Microsoft]19
Win-Trojan/Agent.39936.AP [AhnLab]19
PE_SALITY.AE [Trend Micro]18
Virus.Win32.Sality.l [Kaspersky Lab]18
W32.HLLP.Sality.O [Symantec]18
Backdoor.Win32.Bifrose.cnx [Kaspersky Lab]17
Constructor.Win32.Bifrose [Ikarus]17
Constructor/Bifrose.1905098 [AhnLab]16
Packed.Win32.Black.a [Kaspersky Lab]16
VirTool:Win32/Injector.gen!AG [Microsoft]16
W32.Almanahe.B!inf [Symantec]16
W32/Tuareg-C [Sophos]16
PE_CORELINK.C-1 [Trend Micro]15
Virus.Win32.Alman.b [Kaspersky Lab]15
Virus:Win32/Almanahe.B [Microsoft]15
Virus.Win32.Sality.aa [Kaspersky Lab]14
Win32.Sality.L [PC Tools]14
Win32/Alman.C [AhnLab]14
Backdoor:Win32/Bifrose.ES [Microsoft]13
W32/Almanahe.c [McAfee]13
Win32/Kashu.B [AhnLab]13
Backdoor.Win32.Agent.uek [Kaspersky Lab]12
Backdoor-CEP [McAfee]12
Constructor/Bifrose.1466056 [AhnLab]12
Mal/EncPk-DM [Sophos]12
Virus.Win32.Sality.z [Kaspersky Lab]12
W32/Sality.n [McAfee]12
W32/Sality-I [Sophos]12
Backdoor:Win32/Bifrose.AE [Microsoft]11
Backdoor:Win32/IRCbot.gen!K [Microsoft]11
BackDoor-CEP.gen [McAfee]11
Constructor.Bifrose.FLX [PC Tools]11
Backdoor.Win32.Bifrose.bgn [Kaspersky Lab]10
Packed.Generic.56 [Symantec]10
PE_SALITY.EK [Trend Micro]10
Troj/AgentU-Fam, Mal/Behav-274 [Sophos]10
Win-Trojan/Bifrose.2017280 [AhnLab]10

Virus.Win32.Bifrose [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Sweden857
Saudi Arabia23
Russian Federation15
Brazil12
China8
Germany4
France3
Portugal3
Italy1
Spain1
United Kingdom1

Virus.Win32.Bifrose [Ikarus] is known to be created as:
%AppData%\alg.exe
%AppData%\iexplore.exe
%AppData%\server.exe
%AppData%\setup.exe
%AppData%\update.exe
%AppData%\win.exe
%CommonPrograms%\startup\4444.exe
%CommonPrograms%\startup\81.exe
%LocalSettings%\tempbifrost.exe
%LocalSettings%\tempservices.exe
%LocalSettings%\temptmp.exe
%Profiles%\final.exe
%Profiles%\saad\desktop\ns.exe
%ProgramFiles%\123\imagen1.exe
%ProgramFiles%\acd systemms\acdsee.exe
%ProgramFiles%\bbifros.exe
%ProgramFiles%\bifrost\abd.exe
%ProgramFiles%\bifrost\antivirus32.exe
%ProgramFiles%\bifrost\bifrost.exe
%ProgramFiles%\bifrost\dexter.exe
%ProgramFiles%\bifrost\kos.exe
%ProgramFiles%\bifrost\love.exe
%ProgramFiles%\bifrost\playagain.exe
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\bifrost\wu_crack.exe
%ProgramFiles%\bifrost1.3d_privat.exe
%ProgramFiles%\cat.jpg\server.exe
%ProgramFiles%\config\karimhikal.exe
%ProgramFiles%\ddddddd\dddddd.exe
%ProgramFiles%\drv32z\ksjdssdaf.exe
%ProgramFiles%\dsa\dsa.exe
%ProgramFiles%\explorer\mediaplayer.exe
%ProgramFiles%\freewb\registry.exe
%ProgramFiles%\inf\win86.exe
%ProgramFiles%\internet\windowspak.exe
%ProgramFiles%\java2\java.exe
%ProgramFiles%\messenger live\msnmsngr.exe
%ProgramFiles%\messenger\messenger.exe
%ProgramFiles%\micros\svhoost.exe
%ProgramFiles%\microsoft\experience.exe
%ProgramFiles%\msn\msn.exe
%ProgramFiles%\msn\msnmsgr.exe
%ProgramFiles%\msn\msns.exe
%ProgramFiles%\msnmsnger\msnmsgr.exe
%ProgramFiles%\no-ip\duc20.exe
%ProgramFiles%\original\bifrost1.2d\bifrost1.2d.exe
%ProgramFiles%\probpan\dfvrr.exe
%ProgramFiles%\rabot\rabot.exe
%ProgramFiles%\sock\socker.exe
%ProgramFiles%\system\plugs.exe
%ProgramFiles%\system\star.exe
%ProgramFiles%\system32\server.exe
%ProgramFiles%\system32\win32.exe
%ProgramFiles%\tn_hacker\tn_hacker.exe
%ProgramFiles%\try\ksa.exe
%ProgramFiles%\webmax\server.exe
%ProgramFiles%\wemsn\dovmed.exe
%ProgramFiles%\wimrar\wimrar.exe
%ProgramFiles%\winamp2\winam1p.exe
%ProgramFiles%\windoof\server.exe
%ProgramFiles%\windows live\fingerprint.exe
%ProgramFiles%\windows service\svhost.exe
%ProgramFiles%\windows update\win32update.exe
%ProgramFiles%\windows\explorer.exe
%ProgramFiles%\winfiles\windows.exe
%ProgramFiles%\winrar\bifrost.exe
%ProgramFiles%\winsoft\shell.exe
%ProgramFiles%\yahoomassanger\server.exe
%Programs%\server.exe
%Programs%\startup\dr.mot.exe
%System%\230489\websitr.exe
%System%\6373n\6373n.exe
%System%\ag-sniper\msn.exe
%System%\bifrost.exe
%System%\bifrost\bifrost.exe
%System%\bifrost\dl32.exe
%System%\bifrost\explorer.exe
%System%\bifrost\mouad48.exe
%System%\bifrost\server.exe
%System%\bifrost\sexsexsexs.exe
%System%\bios\bios.exe
%System%\cam\cam2.exe
%System%\dosidf\update.exe
%System%\edf\r.exe
%System%\firefoxdll\sys_undate.exe
%System%\fixweb.exe
%System%\g32pi\svchost.exe
%System%\game\server.exe
%System%\iexplore.exe
%System%\lncom_.exe
%System%\msd0s\ms.exe
%System%\msn.messenger\messenger.exe
%System%\mssngear.exe
%System%\net-cmd\net-cmd.exe
%System%\pcidwn.exe
%System%\powerhost\svcchost.exe
%System%\ramadan.exe
%System%\redidit\instal.exe
%System%\rekey.exe
%System%\server.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %LocalSettings% is a variable that specifies the current user's local settings folder. By default, this is C:\Documents and Settings\[UserName]\Local Settings (Windows NT/2000/XP).
  • %Profiles% is a variable that refers to the file system directory containing user profile folders. A typical path is C:\Documents and Settings.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).