Bifrose.eo

irbullet

BulletsModz
Member
VIP
Local time
3:36 PM
Messages
202
I recently performed a quick scan (MSE) and it found 3 bifrose.eo's.
I quarantined and removed them. It said it was a Backdoor and a severe threat.
Should I be safe now? Or would you suggest something else to do too?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Ultimate x64
CPU
Intel i7 3770K 4.5GHz
Motherboard
MSI Z77A-GD65
Memory
8GB DDR3
Graphics Card(s)
MSI Twin Frozr 7950 (x2) crossfire
Monitor(s) Displays
AOC I2421VWH, LG 27EA63, ASUS VE247H
Screen Resolution
1920x1080 1920x1080 1920x1080
Hard Drives
Intel 330 60GB SSD, Western Digital 1TB, Seagate 1TB
PSU
Rosewill Capstone 750w
Case
Phantom 410
Cooling
IBP-Z001 for CPU and case fans
Keyboard
CM Storm Quickfire Pro
Mouse
Razer Naga 2012
Internet Speed
50 Mbps down, 20 Mbps upload
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Once a computer becomes infected there's always a possibility that additional malware resides somewhere on the hard drive. It could be so deeply buried that all conventional scans fail to find it. Many experts say a clean install of the operating system and all installed programs is the way to go.

Another consideration is no anti-virus or anti-spyware is 100% effective 100% of the time. If there was such a thing we'd all be using it. But the more scans you run using different products, the more likely it is that additional malware might be found. Conversely, the more scans you run that come back clean, the more likely it is your computer is clean (but never 100% sure.) These free products are recommended. You should also run a full MSE scan (may take over an hour to complete.)

Windows Defender Offline (must be created on a malware free computer)

Malwarebytes

ESET Online Scanner

SuperAntispyware

HitmanPro

TSDDKiller

Trend Micro HouseCall (Beta version still being tested, use stable release)

If multiple scans (run just one at a time!) come back clean I'd also suggest checking for any damaged or corrupt system files. Run a system file checker scan from an elevated command prompt (option two.) If problems are found, run the scan 3 times and reboot the computer after each scan.

http://www.sevenforums.com/tutorials/1538-sfc-scannow-command-system-file-checker.html

Please post back the results.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio VPCEB47GM Laptop
OS
Win 7 Pro 64-bit
CPU
Intel i5 2.4 Ghz
Memory
8GB DDR3
Graphics Card(s)
Intel HD 3000
Sound Card
IDT High Definition
Monitor(s) Displays
15.6 WGXA Anti-Glare LED
Screen Resolution
1280x800
Hard Drives
640Gb 7200rpm
Antivirus
MSE
Browser
Opera (primary) with IE9 backup
Once a computer becomes infected there's always a possibility that additional malware resides somewhere on the hard drive. It could be so deeply buried that all conventional scans fail to find it. Many experts say a clean install of the operating system and all installed programs is the way to go.

Another consideration is no anti-virus or anti-spyware is 100% effective 100% of the time. If there was such a thing we'd all be using it. But the more scans you run using different products, the more likely it is that additional malware might be found. Conversely, the more scans you run that come back clean, the more likely it is your computer is clean (but never 100% sure.) These free products are recommended. You should also run a full MSE scan (may take over an hour to complete.)

Windows Defender Offline (must be created on a malware free computer)

Malwarebytes

ESET Online Scanner

SuperAntispyware

HitmanPro

TSDDKiller

Trend Micro HouseCall (Beta version still being tested, use stable release)

If multiple scans (run just one at a time!) come back clean I'd also suggest checking for any damaged or corrupt system files. Run a system file checker scan from an elevated command prompt (option two.) If problems are found, run the scan 3 times and reboot the computer after each scan.

http://www.sevenforums.com/tutorials/1538-sfc-scannow-command-system-file-checker.html

Please post back the results.

MSE removed them.. And im running a malware bytes and another mse scan and hitman pro was clean too
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Ultimate x64
CPU
Intel i7 3770K 4.5GHz
Motherboard
MSI Z77A-GD65
Memory
8GB DDR3
Graphics Card(s)
MSI Twin Frozr 7950 (x2) crossfire
Monitor(s) Displays
AOC I2421VWH, LG 27EA63, ASUS VE247H
Screen Resolution
1920x1080 1920x1080 1920x1080
Hard Drives
Intel 330 60GB SSD, Western Digital 1TB, Seagate 1TB
PSU
Rosewill Capstone 750w
Case
Phantom 410
Cooling
IBP-Z001 for CPU and case fans
Keyboard
CM Storm Quickfire Pro
Mouse
Razer Naga 2012
Internet Speed
50 Mbps down, 20 Mbps upload
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Allows backdoor access and control
Backdoor:Win32/Bifrose.EO may inject code into 'explorer.exe' and 'iexplore.exe' to bypass the firewall without the user's consent. This allows its dropped backdoor malware to attempt to contact one of the following Web sites, possibly to connect to a remote attacker:


  • hassanm.no-ip.org
  • kaboos.no-ip.org

Note that because of the generic nature of this detection, some samples of Backdoor:Win32/Bifrose.EO may be able to perform more specific backdoor functionalities.
Encyclopedia entry: Backdoor:Win32/Bifrose.EO - Learn more about malware - Microsoft Malware Protection Center

Change all passwords for accounts (e.g. banking, forums, Facebook etc.) accessed from this this computer on a different, known clean computer. Change this computers login password/s once you have established it is completely free of malware.

Once clean, check that the firewall is enabled.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Allows backdoor access and control
Backdoor:Win32/Bifrose.EO may inject code into 'explorer.exe' and 'iexplore.exe' to bypass the firewall without the user's consent. This allows its dropped backdoor malware to attempt to contact one of the following Web sites, possibly to connect to a remote attacker:


  • hassanm.no-ip.org
  • kaboos.no-ip.org

Note that because of the generic nature of this detection, some samples of Backdoor:Win32/Bifrose.EO may be able to perform more specific backdoor functionalities.
Encyclopedia entry: Backdoor:Win32/Bifrose.EO - Learn more about malware - Microsoft Malware Protection Center

Change all passwords for accounts (e.g. banking, forums, Facebook etc.) accessed from this this computer on a different, known clean computer. Change this computers login password/s once you have established it is completely free of malware.

Once clean, check that the firewall is enabled.

The firewall is in fact ENABLED. I looked up the registry keys associated with the trojan and I cannot seem to find them. Malware bytes came clean, hitman pro came clean, tdss killer came clean, super anti spyware came clean. I am waiting for the rescan of mse atm, I am running full scans so it is taking a while. after that I'm going to scan with the microsoft tool suggested here
Encyclopedia entry: Backdoor:Win32/Bifrose.EO - Learn more about malware - Microsoft Malware Protection Center
If these all come clean, do you think I'm ok? It may have blocked it before it did anything. I know what it was from too.
How do I check the
  • hassanm.no-ip.org
  • kaboos.no-ip.org
Thing you were talking about?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Ultimate x64
CPU
Intel i7 3770K 4.5GHz
Motherboard
MSI Z77A-GD65
Memory
8GB DDR3
Graphics Card(s)
MSI Twin Frozr 7950 (x2) crossfire
Monitor(s) Displays
AOC I2421VWH, LG 27EA63, ASUS VE247H
Screen Resolution
1920x1080 1920x1080 1920x1080
Hard Drives
Intel 330 60GB SSD, Western Digital 1TB, Seagate 1TB
PSU
Rosewill Capstone 750w
Case
Phantom 410
Cooling
IBP-Z001 for CPU and case fans
Keyboard
CM Storm Quickfire Pro
Mouse
Razer Naga 2012
Internet Speed
50 Mbps down, 20 Mbps upload
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
If MSE comes up clean, then I would say you are OK....but......it won't hurt to do one more using ESET's on-line scanner:
Free Online Virus Scanner | ESET

You can't check for those sites directly - they are the remote sites used for attacks if it gets that far.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
If MSE comes up clean, then I would say you are OK....but......it won't hurt to do one more using ESET's on-line scanner:
Free Online Virus Scanner | ESET

You can't check for those sites directly - they are the remote sites used for attacks if it gets that far.

Ok thanks, I deal with hundreds if not thousands of dollars with my Minecraft server.
I can't afford to have this on my PC, nobody can these days.
I hope it's clean. Everything has came up clean. It's not FUD obviously, It was clear as day. Could it possibly have blocked it before anything happened? I have none of the symptoms associated with it.
But my LIVE account was hacked a few days ago, That or my password messed up which it has before. I got it back with no problem. It has happened before and it was just me being stupid and not entering it right.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Ultimate x64
CPU
Intel i7 3770K 4.5GHz
Motherboard
MSI Z77A-GD65
Memory
8GB DDR3
Graphics Card(s)
MSI Twin Frozr 7950 (x2) crossfire
Monitor(s) Displays
AOC I2421VWH, LG 27EA63, ASUS VE247H
Screen Resolution
1920x1080 1920x1080 1920x1080
Hard Drives
Intel 330 60GB SSD, Western Digital 1TB, Seagate 1TB
PSU
Rosewill Capstone 750w
Case
Phantom 410
Cooling
IBP-Z001 for CPU and case fans
Keyboard
CM Storm Quickfire Pro
Mouse
Razer Naga 2012
Internet Speed
50 Mbps down, 20 Mbps upload
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Could it possibly have blocked it before anything happened?

Yes, its quite possible you caught it in time - monitor your system closely.

But my LIVE account was hacked a few days ago, That or my password messed up which it has before. I got it back with no problem. It has happened before and it was just me being stupid and not entering it right.

Hence my suggestion about passwords, err on the side of caution.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Could it possibly have blocked it before anything happened?

Yes, its quite possible you caught it in time - monitor your system closely.

But my LIVE account was hacked a few days ago, That or my password messed up which it has before. I got it back with no problem. It has happened before and it was just me being stupid and not entering it right.

Hence my suggestion about passwords, err on the side of caution.
thank you so much.
I will come back with my results.
The main reason I don't want to reinstall which would be easy for me is because I have like 90 games installed on steam.. I play most of them.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Ultimate x64
CPU
Intel i7 3770K 4.5GHz
Motherboard
MSI Z77A-GD65
Memory
8GB DDR3
Graphics Card(s)
MSI Twin Frozr 7950 (x2) crossfire
Monitor(s) Displays
AOC I2421VWH, LG 27EA63, ASUS VE247H
Screen Resolution
1920x1080 1920x1080 1920x1080
Hard Drives
Intel 330 60GB SSD, Western Digital 1TB, Seagate 1TB
PSU
Rosewill Capstone 750w
Case
Phantom 410
Cooling
IBP-Z001 for CPU and case fans
Keyboard
CM Storm Quickfire Pro
Mouse
Razer Naga 2012
Internet Speed
50 Mbps down, 20 Mbps upload
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Update:
They all have came back clean. MSE found one thing but it was just a hacktool, it wasn't malicious.
But no more traces of the bifrose.eo!
I hope I'm good now.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Ultimate x64
CPU
Intel i7 3770K 4.5GHz
Motherboard
MSI Z77A-GD65
Memory
8GB DDR3
Graphics Card(s)
MSI Twin Frozr 7950 (x2) crossfire
Monitor(s) Displays
AOC I2421VWH, LG 27EA63, ASUS VE247H
Screen Resolution
1920x1080 1920x1080 1920x1080
Hard Drives
Intel 330 60GB SSD, Western Digital 1TB, Seagate 1TB
PSU
Rosewill Capstone 750w
Case
Phantom 410
Cooling
IBP-Z001 for CPU and case fans
Keyboard
CM Storm Quickfire Pro
Mouse
Razer Naga 2012
Internet Speed
50 Mbps down, 20 Mbps upload
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Change your password and write it down ... save in your undies drawer (or safe place of your choosing :p

You're running a Minecraft server, be diligent with your's and your users' accounts!!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Change your password and write it down ... save in your undies drawer (or safe place of your choosing :p

You're running a Minecraft server, be diligent with your's and your users' accounts!!

Thanks, And I know, If somebody got access. It has many many many many many ip's logged and other stuff on the server account.
That'd be bad.
:cry:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Ultimate x64
CPU
Intel i7 3770K 4.5GHz
Motherboard
MSI Z77A-GD65
Memory
8GB DDR3
Graphics Card(s)
MSI Twin Frozr 7950 (x2) crossfire
Monitor(s) Displays
AOC I2421VWH, LG 27EA63, ASUS VE247H
Screen Resolution
1920x1080 1920x1080 1920x1080
Hard Drives
Intel 330 60GB SSD, Western Digital 1TB, Seagate 1TB
PSU
Rosewill Capstone 750w
Case
Phantom 410
Cooling
IBP-Z001 for CPU and case fans
Keyboard
CM Storm Quickfire Pro
Mouse
Razer Naga 2012
Internet Speed
50 Mbps down, 20 Mbps upload
Antivirus
Microsoft Security Essentials
Browser
Google Chrome
Back
Top