Ransom Trojan

Trojan-Ransom.Win32.Gimemo.bkxo removal guide

Malware Removal

The Trojan-Ransom.Win32.Gimemo.bkxo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Gimemo.bkxo virus can do?

  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r8—sn-bpb5oxu-3c2r.gvt1.com
update.googleapis.com

How to determine Trojan-Ransom.Win32.Gimemo.bkxo?


File Info:

crc32: 0FBA6F8F
md5: 65ad8cd052935e42410d43a5e35871fc
name: 65AD8CD052935E42410D43A5E35871FC.mlw
sha1: ab7eb32f9da0563e340aee6c46b9eab3d411702a
sha256: ad5d2c5362bcf37b8c000c4f399a4d10a7209db3b25a61dfcd80a3ea4d7c3bf2
sha512: ab87c88973cc35d400804fe458c3d362c2d68ef84cd1314b10c6c700016e1649a4897af79d483cb3d03b9fb0e5f3a2e41d51a74f0b763142acbb2c15375a610f
ssdeep: 192:PSJ8T2QaiKVB4hz73Jp+j3Zhj6NU3zhjbP1oynL0kQx:PSeT2Qahaqj3Z1d0kQx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2007
InternalName: WinCapSpy
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: WinCapSpy x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: WinCapSpy Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: WinCapSpy.EXE
Translation: 0x0804 0x04b0

Trojan-Ransom.Win32.Gimemo.bkxo also known as:

DrWebTrojan.Siggen7.55293
CynetMalicious (score: 99)
McAfeeArtemis!65AD8CD05293
CylanceUnsafe
SangforTrojan.Win32.GenericKDV.brYV
SymantecTrojan.Dropper
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gimemo.bkxo
NANO-AntivirusTrojan.Win32.Gimemo.cllntb
TencentWin32.Trojan.Gimemo.Wpjx
SophosMal/Generic-S
ComodoMalware@#1yj9unzu7y6to
F-SecureTrojan.TR/Ransom.Gimemo.bkxo.1
BitDefenderThetaGen:NN.ZexaCO.34758.bq0@ay3ymSob
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
JiangminTrojan/Gimemo.hcq
AviraTR/Ransom.Gimemo.bkxo.1
Antiy-AVLTrojan/Generic.ASMalwS.5AB05A
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Dynamer!ac
ZoneAlarmTrojan-Ransom.Win32.Gimemo.bkxo
VBA32BScope.TrojanRansom.Gimemo
MAXmalware (ai score=100)
PandaGeneric Malware
YandexTrojan.Gimemo!jFNF3KxJsMI
FortinetW32/Gimemo.BKXO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Gimemo.bkxo?

Trojan-Ransom.Win32.Gimemo.bkxo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment