Backdoor

Backdoor:Win32/Rifdoor.B!bit removal tips

Malware Removal

The Backdoor:Win32/Rifdoor.B!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Rifdoor.B!bit virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor:Win32/Rifdoor.B!bit?


File Info:

name: BD8475103F948387435E.mlw
path: /opt/CAPEv2/storage/binaries/1e52b603b0604308da651f641fb623507d918fd9936d427e79c29f36f3b66fa4
crc32: C005AB78
md5: bd8475103f948387435ea3df5ca24d76
sha1: 81d255126bf24f950f12172b8804b87467023b4d
sha256: 1e52b603b0604308da651f641fb623507d918fd9936d427e79c29f36f3b66fa4
sha512: 07ea3ef8b1b74e356e5e929b4c18f744a2649152cdc192947a8a2d18d5097d9cc1ab0040dc9687c3e87e25b41489822851f411d999d5d0d0f63760836a7e77f0
ssdeep: 1536:IE3qz4ayX9ioT5Xl8lQWj1vTo5G6kvBzodfjZw4jk5tGwts1P:179l86WqGzIfjZwik5tE1P
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9A38D11B881C573C04A95711499E7B2AB3DF9316A79A583F38D0FBA5FB02D0663E387
sha3_384: e35a5b2bd90c4aaff4715e53a911a26dfd612a1d74de397a862b9db5bc092ecb0eb12462ef3f5fc7fae8fea6292c0aa0
ep_bytes: e8ea650000e978feffff8bff558bec51
timestamp: 2012-07-26 18:49:30

Version Info:

0: [No Data]

Backdoor:Win32/Rifdoor.B!bit also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.34441
MicroWorld-eScanTrojan.GenericKD.37920560
FireEyeGeneric.mg.bd8475103f948387
CAT-QuickHealTrojan.Dynamer.8881
McAfeeGenericRXEO-DF!BD8475103F94
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforWorm.Win32.Save.a
K7AntiVirusTrojan ( 004c47121 )
K7GWTrojan ( 004c47121 )
Cybereasonmalicious.03f948
BitDefenderThetaAI:Packer.DD3671A21F
CyrenW32/S-0ee6d6bf!Eldorado
SymantecBackdoor.Waketagat
ESET-NOD32Win32/Spy.Keydoor.AD
TrendMicro-HouseCallTSPY_HPURSNIF.SM1
ClamAVWin.Malware.Scar-9776391-0
KasperskyTrojan.Win32.Scar.ojnn
BitDefenderTrojan.GenericKD.37920560
NANO-AntivirusTrojan.Win32.TrjGen.drufdw
AvastWin32:BackDoor-AFV [Trj]
RisingSpyware.Keydoor!1.B6A0 (CLASSIC)
Ad-AwareTrojan.GenericKD.37920560
EmsisoftTrojan.GenericKD.37920560 (B)
ComodoTrojWare.Win32.Agent.XYZ@6l9auh
BaiduWin32.Trojan.Agent.avd
ZillyaTrojan.Katusha.Win32.38343
TrendMicroTSPY_HPURSNIF.SM1
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosML/PE-A + Troj/Scar-CV
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Spy.Ursnif.K
JiangminTrojan/Generic.beovz
AviraTR/Agent.106509
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.1039187
ArcabitTrojan.Generic.D2429F30
ViRobotBackdoor.Win32.Agent.106526
MicrosoftBackdoor:Win32/Rifdoor.B!bit
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bmbot.C792257
Acronissuspicious
VBA32Trojan.Scar
ALYacTrojan.Agent.Spear16F1
MalwarebytesSpyware.Keydoor
APEXMalicious
TencentTrojan.Win32.BitCoinMiner.la
YandexTrojan.Agent!v5BuXtqGM7w
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Scar.OETR
FortinetW32/Agent.XFS!tr
AVGWin32:BackDoor-AFV [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor:Win32/Rifdoor.B!bit?

Backdoor:Win32/Rifdoor.B!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment