Trojan

About “Trojan:Win32/Rifdoor.RA!MTB” infection

Malware Removal

The Trojan:Win32/Rifdoor.RA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Rifdoor.RA!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Rifdoor.RA!MTB?


File Info:

name: 5DBBC68CA79ADA93E751.mlw
path: /opt/CAPEv2/storage/binaries/bde85aeb0cbf38ee26ee5d9a91b9de106c7dbd22fe630e7f97a7eaba6cda3c64
crc32: 40734544
md5: 5dbbc68ca79ada93e75121f23bd3c605
sha1: b4c85f72a046c3f1df037587110c0db710494b20
sha256: bde85aeb0cbf38ee26ee5d9a91b9de106c7dbd22fe630e7f97a7eaba6cda3c64
sha512: 7bd2900f65c05e5fad411d0a91da86df43f6b52859985f9fafae2562735b81f8c60f268556677a1a2548006d7b1d1e9cef7b5d137804f2ea2ca773e6e1f0c5bc
ssdeep: 1536:OrLJCCtCtJ1N0XZmu2wRM7lb+8ixCvPMWk3jhzRZICrWaGZhg:OXJNtYNkRBGixCvPMWk3jvJrWNZa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10DC38D10BA50C472D89215349877E2A25B79BC3257B485C3B7FC1BAF6FB03C1A53A35A
sha3_384: a56f4bc463fa1e380e7e3c311c004b51aef35711c1658d2f6914b71ca92acf47e321bc58c7647c0df017a869dc8cce22
ep_bytes: 95e8feffff52ff15b4c0c3008b4dfc5e
timestamp: 2015-11-24 04:03:06

Version Info:

0: [No Data]

Trojan:Win32/Rifdoor.RA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Dacic.4!c
MicroWorld-eScanGeneric.Dacic.06B5CF0E.A.27197AF5
FireEyeGeneric.mg.5dbbc68ca79ada93
McAfeeArtemis!5DBBC68CA79A
Cylanceunsafe
ZillyaTrojan.GenKryptik.Win32.211488
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a8b941 )
AlibabaTrojan:Win32/Rifdoor.696f1a22
K7GWTrojan ( 005a8b941 )
CyrenW32/Agent.FEH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/GenKryptik.GAFN
APEXMalicious
ClamAVWin.Malware.Agentb-9639796-0
BitDefenderGeneric.Dacic.06B5CF0E.A.27197AF5
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Kryptik.Qsmw
SophosMal/Generic-S
F-SecureTrojan.TR/Kryptik.aqoiu
VIPREGeneric.Dacic.06B5CF0E.A.27197AF5
TrendMicroTROJ_GEN.R03BC0DFO23
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
EmsisoftGeneric.Dacic.06B5CF0E.A.27197AF5 (B)
IkarusTrojan.Crypt
GDataGeneric.Dacic.06B5CF0E.A.27197AF5
GoogleDetected
AviraTR/Kryptik.aqoiu
ArcabitGeneric.Dacic.06B5CF0E.A.27197AF5
MicrosoftTrojan:Win32/Rifdoor.RA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Rifdoor.R575624
ALYacGeneric.Dacic.06B5CF0E.A.27197AF5
MAXmalware (ai score=82)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DFO23
RisingTrojan.Agent!1.DAE9 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.GAFN!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Rifdoor.RA!MTB?

Trojan:Win32/Rifdoor.RA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment