Trojan

Trojan:Win32/Rimecud!pz removal tips

Malware Removal

The Trojan:Win32/Rimecud!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Rimecud!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Creates a copy of itself
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Rimecud!pz?


File Info:

name: A75079FC34A581D502F4.mlw
path: /opt/CAPEv2/storage/binaries/6ce0e35f42cf1c4d72d886cc833139854d11b6613065c44d7ac8465830d89a44
crc32: C9485F72
md5: a75079fc34a581d502f44d35155070fa
sha1: cfc0a1877c189e389d4e7958606b349a1f56cb7d
sha256: 6ce0e35f42cf1c4d72d886cc833139854d11b6613065c44d7ac8465830d89a44
sha512: 3b033186daf9687544d040535cad526119da13412a01f4e63ac931d780b3b2bc9524ce02eb369f8f96083fdf130b1738f997c5b101eff69a4c54bad35d74b571
ssdeep: 1536:HA95ZLeqmJho8/Vq0nRrSX01P06+28nN/YbxEJ3ZgVFyBGHTXH:HA9eqmV7nxSk1cE8FkxwcR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16DA3D01CB6A08279F1A21EF8197D3299CE5DBFA19731469F43003DAE89722D1CCB8B55
sha3_384: be9e62e0c03f6e3650d431806a6ac217eb2d3c2e4fdcc441e185cf4a9cd4d93326983ebcfc2a2be4cd4c32ed17fbf8ba
ep_bytes: 8bff558bec81ecfc0000000fce6a30e8
timestamp: 2009-05-08 05:19:55

Version Info:

0: [No Data]

Trojan:Win32/Rimecud!pz also known as:

BkavW32.FakeW7Folder.Fam.Trojan
LionicTrojan.Win32.Buzus.kZ0o
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Agiala.4
ClamAVWin.Trojan.Rimecud-13782
FireEyeGeneric.mg.a75079fc34a581d5
CAT-QuickHealTrojan.Rimecud.BB
SkyhighBehavesLike.Win32.Generic.ch
ALYacGen:Variant.Agiala.4
Cylanceunsafe
ZillyaWorm.Bflient.Win32.636
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 0021289e1 )
K7AntiVirusTrojan ( 0021289e1 )
ArcabitTrojan.Agiala.4
SymantecW32.Pilleuz!gen19
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Bflient.AC
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Agiala.4
NANO-AntivirusTrojan.Win32.Bflient.elxcnx
AvastWin32:Morphex [Cryp]
TencentMalware.Win32.Gencirc.13b4ac65
EmsisoftGen:Variant.Agiala.4 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.Packed.21635
VIPREGen:Variant.Agiala.4
TrendMicroWORM_PALEVO.SMEX
Trapminemalicious.high.ml.score
SophosMal/EncPk-XN
IkarusTrojan.Win32.Rimecud
JiangminWorm/Generic.efa
GoogleDetected
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Bflient.~AD4@3d18wz
MicrosoftTrojan:Win32/Rimecud!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Agiala.4
VaristW32/Rimecud.R.gen!Eldorado
AhnLab-V3Win32/Palevo15.worm.Gen
McAfeeGeneric Dropper.yd
MAXmalware (ai score=100)
VBA32BScope.Trojan.MTA.0904
MalwarebytesTrojan.Downloader
PandaTrj/Rimecud.a
TrendMicro-HouseCallWORM_PALEVO.SMEX
RisingMalware.XPACK!1.657C (CLASSIC)
YandexTrojan.GenAsa!jPBMtRcZ62c
FortinetW32/Palevo.RB!tr
AVGWin32:Morphex [Cryp]
Cybereasonmalicious.77c189
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Rimecud!pz?

Trojan:Win32/Rimecud!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment