Trojan

What is “Trojan:Win32/Rimecud!pz”?

Malware Removal

The Trojan:Win32/Rimecud!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Rimecud!pz virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Rimecud!pz?


File Info:

name: E24BB79DE54C30C0812E.mlw
path: /opt/CAPEv2/storage/binaries/19883a40d5fbcbf5aec1a61da5978eb9df3c0d51d5591c2225fe026f1f18d7cd
crc32: 25106194
md5: e24bb79de54c30c0812e25960a8d8848
sha1: 0ea68e3d7d840997d36cd0d8e09604db7b280e04
sha256: 19883a40d5fbcbf5aec1a61da5978eb9df3c0d51d5591c2225fe026f1f18d7cd
sha512: b2c50b60166d52bb915747768b8eef7ce4f79f0a4bbabb9b7c0c6c9bb8172ecd3b5f56b3cf31dc835810fe2eb0e99320c6521772fa5a8e675cd428e0d8b82687
ssdeep: 3072:hhtE7T8AVotp/RyTfX+EGnPtBxI9qumPyy1ausVd8:hhYwAatp/RLEGVBqchaHV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9A3E04C5243EDD0D4A20A3043CB9B93EE65AF38AC6B1BC6BA94371FFE775C1111A246
sha3_384: a7eeba83b4e26f2293ce7d10d1ac17b98ec6a56e7afadf4c3a89e617734b14736f1f186c1b6d4735decf7ac379e5e2f8
ep_bytes: 60be008041008dbe0090feff57eb0b90
timestamp: 2007-04-09 10:20:05

Version Info:

CompanyName: Ltygwbxe Qe
FileDescription: Bibajphh, Hsonoq
FileVersion: 2.5.4300.2600
InternalName: Fjxavt Esojo. Ushquck
LegalCopyright: Iyia Refpjyoq Vx
OriginalFilename: Pngvcue
ProductName: Qjhqfhofg Gjkwnfy
ProductVersion: 2.5.4300.2600
Translation: 0x0409 0x04b0

Trojan:Win32/Rimecud!pz also known as:

BkavW32.RandomNoteQKA.Fam.Trojan
LionicWorm.Win32.Palevo.o!c
tehtrisGeneric.Malware
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Rimecud.AA
SkyhighBredolab.gen.ad
ALYacGen:Variant.Bredo.20
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Variant.Bredo.20
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004efe241 )
BitDefenderGen:Variant.Bredo.20
K7GWTrojan ( 004efe241 )
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.Bredo.20
BaiduWin32.Trojan.Kryptik.adk
SymantecW32.Pilleuz!gen19
ESET-NOD32a variant of Win32/Bflient.L
APEXMalicious
KasperskyP2P-Worm.Win32.Palevo.jub
AlibabaWorm:Win32/Palevo.b97c3932
NANO-AntivirusTrojan.Win32.Palevo.biaqsh
MicroWorld-eScanGen:Variant.Bredo.20
AvastWin32:Crumpache [Cryp]
RisingTrojan.Generic@AI.100 (RDMK:v8Cmqo4EUO28BNZp7Thd+A)
EmsisoftGen:Variant.Bredo.20 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Packed.20312
ZillyaWorm.Palevo.Win32.122166
TrendMicroWORM_PALEVO.SMGS
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.e24bb79de54c30c0
SophosMal/FakeAV-EW
SentinelOneStatic AI – Malicious PE
JiangminPacked.Katusha.pnr
VaristW32/Rimecud.J.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLWorm[P2P]/Win32.Palevo
KingsoftWin32.Troj.Undef.a
XcitiumWorm.Win32.Palevo.~JUB@2ofl6x
MicrosoftTrojan:Win32/Rimecud!pz
ZoneAlarmP2P-Worm.Win32.Palevo.jub
GDataGen:Variant.Bredo.20
GoogleDetected
AhnLab-V3Worm/Win32.Palevo.R136137
McAfeeArtemis!E24BB79DE54C
VBA32BScope.Trojan.MTA.0904
Cylanceunsafe
PandaTrj/Rimecud.a
TrendMicro-HouseCallWORM_PALEVO.SMGS
TencentMalware.Win32.Gencirc.140317b0
YandexWorm.Palevo.Gen!Pac.8
IkarusP2P-Worm.Win32.Palevo
MaxSecureTrojan.Malware.1337535.susgen
FortinetW32/Kryptik.ANP!tr
BitDefenderThetaAI:Packer.6104F5101F
AVGWin32:Crumpache [Cryp]
Cybereasonmalicious.de54c3
DeepInstinctMALICIOUS
alibabacloudWorm[p2p]:Win/Bflient.L

How to remove Trojan:Win32/Rimecud!pz?

Trojan:Win32/Rimecud!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment