Backdoor

Backdoor.Rifdoor removal instruction

Malware Removal

The Backdoor.Rifdoor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Rifdoor virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Backdoor.Rifdoor?


File Info:

name: ED253B37036F323310E0.mlw
path: /opt/CAPEv2/storage/binaries/4e06f0b5182bc3e2ec2b2ea628bd1e4dee7f03e163b7491618bc8ad468f5dd35
crc32: EEE16F87
md5: ed253b37036f323310e0c7bc58505741
sha1: 0fd2fa1722089b715a7f2e5161a29af1246276cc
sha256: 4e06f0b5182bc3e2ec2b2ea628bd1e4dee7f03e163b7491618bc8ad468f5dd35
sha512: 06c943342b0a63f7900c6afc3070a87e5a78d7629b379a9e97c4cb26c14eaadda5434515f276cb413cca164a3d64bc66f1ef8e435e935bbfa9093b2251e8bd81
ssdeep: 1536:0H5IyjVy2n2qbLnSyFcOk9BUMXHSHYLotWd18:0Htph/nFEnpHSHYLotWd18
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FB37B107290C832F1A20A354869D3724A7DBD3366B5C9C77BC81AEE5F707D06A7936B
sha3_384: 1f36190a964a058a6d1cb5fbbc05645277e79aced646a9923ca2cccfc0a1a50ba8e1ae9f262d3476f168eba857e14b2a
ep_bytes: 51ff15e4c0fc00807d98008d4598740d
timestamp: 2016-01-30 00:31:12

Version Info:

0: [No Data]

Backdoor.Rifdoor also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ulise.419387
ClamAVWin.Malware.Bqrf-9645595-0
FireEyeGeneric.mg.ed253b37036f3233
CAT-QuickHealBackdoor.Rifdoor
ALYacGen:Variant.Ulise.419387
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Ulise.419387
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.722089
CyrenW32/Agent.GHN.gen!Eldorado
SymantecBackdoor.Rifelku
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Ulise.419387
EmsisoftGen:Variant.Ulise.419387 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
TrendMicroTROJ_GEN.R03BC0DIB23
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1IVUW0B
AviraTR/Patched.Ren.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[Backdoor]/Win32.Rifdoor
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Ulise.D6663B
MicrosoftBackdoor:Win32/Rifdoor.A!bit
GoogleDetected
AhnLab-V3Trojan/Win32.Rifdoor.R346726
Acronissuspicious
McAfeeGenericRXAA-FA!ED253B37036F
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DIB23
RisingTrojan.Agent!1.DAE9 (CLASSIC)
IkarusTrojan.Win32.Andariel
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Ulise.DAIC!tr
BitDefenderThetaGen:NN.ZexaF.36662.huY@a46Ljhc
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor.Rifdoor?

Backdoor.Rifdoor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment