Trojan

Should I remove “Trojan:Win32/Rifdoor!pz”?

Malware Removal

The Trojan:Win32/Rifdoor!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Rifdoor!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Rifdoor!pz?


File Info:

name: B1342ED991AB8C623D90.mlw
path: /opt/CAPEv2/storage/binaries/72bd59d2568d2e3254ad03323d5f10f0e2529ea165d2a2b40565c797f60bfffb
crc32: 7B5E31E3
md5: b1342ed991ab8c623d904647f8ec6d3a
sha1: 254b01c81ed208850348918f1fb2a15d5ab25829
sha256: 72bd59d2568d2e3254ad03323d5f10f0e2529ea165d2a2b40565c797f60bfffb
sha512: 71c4c4d6a797096d4a21e407a2c2cf6d4bb18ad91b2c38a5ea661ad5825ffdd9e97080088405c630bb4199f2e4aea67375c0f350fd13c443fc5dd231b063ccf9
ssdeep: 1536:0o6Of0Lv6DHtkRW6fz5UtfVgx5HsphiZXBWXD6sezRZICrWaGZh7i:0jOf0LwkrtekSiZXBWXD6hJrWNZI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137C39E01B242C432D0951534887AD7B15A79BC3296B991CB77D8EBEF6FB03C1D63A326
sha3_384: 85e3f7e095c3ee7b47ad1ec2023b6ea5388078ee6e048d9444c827be2334fb3094ac63497f0dc218af569eec188f1079
ep_bytes: 8b85f8feffff50ffd385f674548d8df8
timestamp: 2015-11-24 04:03:06

Version Info:

0: [No Data]

Trojan:Win32/Rifdoor!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.Dacic.06B5CF0E.A.D95882C5
CAT-QuickHealTrojan.Rifdoor
SkyhighBehavesLike.Win32.Generic.cm
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.GenKryptik.Win32.266404
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a8b941 )
K7GWTrojan ( 005a8b941 )
Cybereasonmalicious.81ed20
ArcabitGeneric.Dacic.06B5CF0E.A.D95882C5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.GAFN
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Agentb-9639796-0
KasperskyHEUR:Trojan.Win32.ChompStays.gen
BitDefenderGeneric.Dacic.06B5CF0E.A.D95882C5
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.ChompStays.ka
SophosML/PE-A
VIPREGeneric.Dacic.06B5CF0E.A.D95882C5
TrendMicroTROJ_GEN.R03BC0DAG24
EmsisoftGeneric.Dacic.06B5CF0E.A.D95882C5 (B)
IkarusTrojan.Win32.Agent
VaristW32/Agent.FEH.gen!Eldorado
Antiy-AVLTrojan/Win32.GenKryptik
Kingsoftmalware.kb.a.978
MicrosoftTrojan:Win32/Rifdoor!pz
ZoneAlarmHEUR:Trojan.Win32.ChompStays.gen
GDataWin32.Trojan.Rifle.A
GoogleDetected
AhnLab-V3Trojan/Win.Rifdoor.R511617
BitDefenderThetaGen:NN.ZexaCO.36680.hyY@a4Idv3k
ALYacGeneric.Dacic.06B5CF0E.A.D95882C5
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DAG24
RisingTrojan.Agent!1.DAE9 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.GAFN!dam
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Rifdoor!pz?

Trojan:Win32/Rifdoor!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment