Trojan

About “Trojan.Rimod.AZ3” infection

Malware Removal

The Trojan.Rimod.AZ3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Rimod.AZ3 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Attempts to disable or modify Explorer Folder Options
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Rimod.AZ3?


File Info:

name: E2E4F4BD98D3D319A5A9.mlw
path: /opt/CAPEv2/storage/binaries/421e54c7f8ba88c6a2c74af52576d6bb8c9efb3f13c65402bd57b5faf9ab854d
crc32: 58CA121D
md5: e2e4f4bd98d3d319a5a91949c9d61d2e
sha1: 0a3d75a89bae9be68453f00e3fbf2faa03a811fc
sha256: 421e54c7f8ba88c6a2c74af52576d6bb8c9efb3f13c65402bd57b5faf9ab854d
sha512: 9fe8c99c888dbf1b7fc65498b5db14a74722f5c960cf322bf734c5763ec64a513b1c1c4a6d3a717f47385a13b68c24fe05b4d975a4fe2f5d32c242f86d6969a6
ssdeep: 768:GpQNwC3BEddFEqOt/hyJF+x3BEJwRrPoC:meTcP/U/hKYuKP/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14873D643B752C680F5496179688387A96793FD70AE037A075150FF3F3AB39A14E91B22
sha3_384: 3ea2fe50d84db77765d356df48dbc0546e3779fc09b89c88abd46f09c663b0abb877126b4312d2daf7a162560d5b42b3
ep_bytes: 68186d4000e8f0ffffff000000000000
timestamp: 2009-01-06 03:24:42

Version Info:

Translation: 0x0409 0x04b0
ProductName: Microsoft Windows
FileVersion: 1.00.0050
ProductVersion: 1.00.0050
InternalName: music
OriginalFilename: music.exe

Trojan.Rimod.AZ3 also known as:

BkavW32.FamVT.ViselPM.Worm
LionicTrojan.Win32.Vilsel.lQNo
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.74328
FireEyeTrojan.GenericKDZ.74328
CAT-QuickHealTrojan.Rimod.AZ3
ALYacTrojan.GenericKDZ.74328
Cylanceunsafe
ZillyaTrojan.Vilsel.Win32.4241
SangforWorm.Win32.VB.pro3
K7AntiVirusTrojan ( 005640b91 )
AlibabaTrojan:Win32/Vilsel.455
K7GWP2PWorm ( 004e46c61 )
Cybereasonmalicious.d98d3d
BitDefenderThetaAI:Packer.0AFB10C121
VirITTrojan.Win32.Generic.AZOV
CyrenW32/Vilsel.DJKY-0547
SymantecTrojan.Dropper
Elasticmalicious (high confidence)
ESET-NOD32Win32/VB.THB
APEXMalicious
ClamAVWin.Malware.Genpack-6989317-0
KasperskyTrojan.Win32.Vilsel.bpxe
BitDefenderTrojan.GenericKDZ.74328
NANO-AntivirusTrojan.Win32.Vilsel.cqkyek
SUPERAntiSpywareTrojan.Agent/Gen-Vilsel
AvastWin32:VB-AEMS [Trj]
TencentTrojan.Win32.VB.blb
TACHYONTrojan/W32.Vilsel.73918.B
EmsisoftTrojan.GenericKDZ.74328 (B)
BaiduWin32.Trojan.VB.h
F-SecureTrojan.TR/VB.Agent.hefjn
DrWebTrojan.Siggen2.50583
VIPRETrojan.GenericKDZ.74328
TrendMicroWORM_VB.SMCK
McAfee-GW-EditionBehavesLike.Win32.Vilsel.lt
Trapminemalicious.high.ml.score
SophosTroj/VB-EUH
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Vilsel.A
JiangminTrojan/Vilsel.xtz
WebrootW32.Rimod.Gen
GoogleDetected
AviraTR/VB.Agent.hefjn
Antiy-AVLTrojan/Win32.Vilsel
XcitiumTrojWare.Win32.Vilsel.ALY@4bdezk
ArcabitTrojan.Generic.D12258
ViRobotTrojan.Win32.A.Vilsel.73756.A
ZoneAlarmTrojan.Win32.Vilsel.bpxe
MicrosoftTrojan:Win32/Vindor!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Vilsel.R1968
McAfeeGeneric VB.aaal
MAXmalware (ai score=100)
VBA32SScope.Trojan.VB
MalwarebytesChir.Spyware.Infostealer.DDS
PandaTrj/Vilsel.AM
TrendMicro-HouseCallWORM_VB.SMCK
RisingTrojan.VB!1.BE89 (CLASSIC)
YandexTrojan.GenAsa!fpIOh2aUKFk
IkarusTrojan.VB.Agent
MaxSecureTrojan.Vilsel.aly
FortinetW32/Agent.OZA!worm
AVGWin32:VB-AEMS [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Rimod.AZ3?

Trojan.Rimod.AZ3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment