Ransom Trojan

How to remove “Trojan-Ransom.Win32.Gimemo.rms”?

Malware Removal

The Trojan-Ransom.Win32.Gimemo.rms is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Gimemo.rms virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Ransom.Win32.Gimemo.rms?


File Info:

crc32: E951F8E9
md5: dc9fa5f97a34e19be958a84693d24bdd
name: DC9FA5F97A34E19BE958A84693D24BDD.mlw
sha1: 548611b3a6cfdab4a7a028cea89f844ea46eab68
sha256: 0787058942edf9bf06d5bf6a95bb129b05f98e88eb6725d5a7787309ee329b42
sha512: dc64a1140dbb6421cd224202b9f486f1d47164c9034fdea6e7118ef564cb0f9f65a80d4e9c5338b07d3a6ac15936287a314d64b78b2b421ca046b2a569f7e02c
ssdeep: 3072:lrzgzXMT8IRBBsg0zlmXDQWmtlPfZpdQGF4REr1Lamvz9KNmI:RzkX+5BCPkDIBH4REkI94
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Gimemo.rms also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e3991 )
Elasticmalicious (high confidence)
DrWebBackDoor.Andromeda.22
CynetMalicious (score: 100)
CAT-QuickHealTrojanRansom.Gimemo
ALYacGen:Variant.Kazy.59405
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.1984
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Gimemo.8032d79b
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.97a34e
CyrenW32/Gimemo.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.QWV
APEXMalicious
AvastWin32:Citadel [Trj]
ClamAVWin.Trojan.Gimemo-30
KasperskyTrojan-Ransom.Win32.Gimemo.rms
BitDefenderGen:Variant.Kazy.59405
NANO-AntivirusTrojan.Win32.Gimemo.qtesv
ViRobotTrojan.Win32.A.Gimemo.214567
MicroWorld-eScanGen:Variant.Kazy.59405
TencentMalware.Win32.Gencirc.10b492c2
Ad-AwareGen:Variant.Kazy.59405
SophosMal/Generic-R + Troj/Zbot-BUF
ComodoTrojWare.Win32.Spy.Zbot.DTNY@4pp6dp
F-SecureTrojan.TR/Ransom.Gimemo.jh
BitDefenderThetaGen:NN.ZexaF.34690.nuZ@a8lcqfic
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-Zbot.gen.ym
FireEyeGeneric.mg.dc9fa5f97a34e19b
EmsisoftGen:Variant.Kazy.59405 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Gimemo.bvv
WebrootW32.InfoStealer.Zeus
AviraTR/Ransom.Gimemo.jh
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftVirTool:Win32/Obfuscator.XS
ArcabitTrojan.Kazy.DE80D
AegisLabTrojan.Win32.Gimemo.tnBx
ZoneAlarmTrojan-Ransom.Win32.Gimemo.rms
GDataGen:Variant.Kazy.59405
TACHYONTrojan/W32.Gimemo.214567
AhnLab-V3Trojan/Win32.Gimemo.R25158
McAfeePWS-Zbot.gen.ym
MAXmalware (ai score=100)
VBA32Hoax.Gimemo
MalwarebytesMalware.AI.2619437411
PandaTrj/Genetic.gen
RisingTrojan.Win32.Generic.12CDB0EB (C64:YzY0OqUycPLIS3Hc)
YandexTrojan.GenAsa!FrwBUB+zndc
IkarusTrojan-Ransom.Gimemo
MaxSecureTrojan.Malware.3940400.susgen
FortinetW32/Kryptik.WDW!tr
AVGWin32:Citadel [Trj]
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Gimemo.rms?

Trojan-Ransom.Win32.Gimemo.rms removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment