Ransom Trojan

Trojan-Ransom.Win32.Gimemo.arvh removal

Malware Removal

The Trojan-Ransom.Win32.Gimemo.arvh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Gimemo.arvh virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan-Ransom.Win32.Gimemo.arvh?


File Info:

name: D809CC567D2AC054D7A6.mlw
path: /opt/CAPEv2/storage/binaries/34e4e9939ba07c2d71f1dc9406e2e4870a7b42d9eb9e3cb03b1e4f79016bb535
crc32: C90C0D1B
md5: d809cc567d2ac054d7a6b8746eb4783b
sha1: 0acb2fcfb6cfc4afd05789f56761a05ad5e0310b
sha256: 34e4e9939ba07c2d71f1dc9406e2e4870a7b42d9eb9e3cb03b1e4f79016bb535
sha512: 9150b9af17d904747aa85d176ecbb5cf6dff342bcf22a3a00bed69731d07b99b3b89e5c5015a74e6a134cd24fffc5a1361db59b1b592d3e8c654d8abb359f20f
ssdeep: 768:EhJGtreAtXZ9ZlqJAs32xp9JIVk8GlLy:EhkreAtplqJADp9JIVw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BD137B369A83B032C414B9BE5D69B348FE3F7B630924946B7BD91DDC4C6DA25AC4C10B
sha3_384: 0b3a5d540efbba356cf054b106765d3431602595b736e9926b25ab0268ae076231a50b3b5e35f34d7e7850c62785b04f
ep_bytes: 558becb90f0000006a006a004975f953
timestamp: 2012-10-06 10:09:10

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Gimemo.arvh also known as:

LionicTrojan.Win32.Gimemo.j!c
DrWebTrojan.Hosts.6156
MicroWorld-eScanGen:Trojan.Heur.DP.cKW@a4pfd3n
FireEyeGen:Trojan.Heur.DP.cKW@a4pfd3n
McAfeeArtemis!D809CC567D2A
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.3923
K7AntiVirusTrojan ( 0028cceb1 )
K7GWTrojan ( 0028cceb1 )
Cybereasonmalicious.67d2ac
BitDefenderThetaAI:Packer.463B297C1E
VirITTrojan.Win32.Small.EEK
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Qhost.PED
APEXMalicious
KasperskyTrojan-Ransom.Win32.Gimemo.arvh
BitDefenderGen:Trojan.Heur.DP.cKW@a4pfd3n
NANO-AntivirusTrojan.Win32.Gimemo.duisfi
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.114c2058
Ad-AwareGen:Trojan.Heur.DP.cKW@a4pfd3n
TACHYONRansom/W32.DP-Gimemo.43520
EmsisoftGen:Trojan.Heur.DP.cKW@a4pfd3n (B)
ComodoMalware@#3gzfhaowx29nk
VIPREGen:Trojan.Heur.DP.cKW@a4pfd3n
McAfee-GW-EditionBehavesLike.Win32.Infected.ph
SophosMal/Generic-S
GDataGen:Trojan.Heur.DP.cKW@a4pfd3n
JiangminTrojan/Gimemo.ejj
WebrootW32.Malware.Gen
GoogleDetected
AviraHEUR/AGEN.1218573
Antiy-AVLTrojan/Generic.ASMalwS.294
ViRobotTrojan.Win32.A.Gimemo.43520.A
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
VBA32Hoax.Gimemo
ALYacGen:Trojan.Heur.DP.cKW@a4pfd3n
MAXmalware (ai score=83)
RisingMalware.Undefined!8.C (TFE:4:uVJ3rTf7PLG)
YandexTrojan.GenAsa!nIHrkMdLyF8
IkarusTrojan-Ransom.Gimemo
FortinetW32/Qhost.PED!tr
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan-Ransom.Win32.Gimemo.arvh?

Trojan-Ransom.Win32.Gimemo.arvh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment