Trojan

Trojan:Win32/Rimecud!pz malicious file

Malware Removal

The Trojan:Win32/Rimecud!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Rimecud!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Rimecud!pz?


File Info:

name: 7C8DAD0B3881CE960EFB.mlw
path: /opt/CAPEv2/storage/binaries/a8743ca1f27e950d8d8ab9f82564ba380786724f74f86ad07003d9e6eb09ee5c
crc32: 08BE572A
md5: 7c8dad0b3881ce960efbadb0e39de3f0
sha1: 95753b7aaaad48ceaa4f42d6b3a8898cfbfad116
sha256: a8743ca1f27e950d8d8ab9f82564ba380786724f74f86ad07003d9e6eb09ee5c
sha512: 863a2fe152e7574ba7e08b67becac3018f3228b8b3ce4273b74dcb3a71810878bc783a517a07f56db0fdd9225cfca6d4a1a1a109e43efe7f3b7a2c5601b61b05
ssdeep: 1536:0k9HxEtybZRaahup6O4+df88z/pEI1lwNXfBgSpYklXo++gcM5BbbQnxbAAcHER:BHxNlRHhFOh/pE6lwtWSPlp+2nghJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10FC39E90D2D0E1E7E4BA54B07263C93437A7AD1464782B3A219C727669713877CBFC2B
sha3_384: 1923f81225acd892544fb3b8f7905a740ece6f01b897c1b6c8e1efe4a77a9cab1a958a610267665a6912d57465b87587
ep_bytes: 558bec6aff6810304000688511400064
timestamp: 2010-03-01 17:10:15

Version Info:

Comments: lol
CompanyName: Trend Micro
FileDescription: Trend Micro AntiVirus Plus AntiSpyware
FileVersion: 17.50.0.1366
InternalName: 7zsfx.exe
LegalCopyright: Copyright (C) 1995-2012 Trend Micro Incorporated. All rights reserved.
LegalTrademarks: Copyright (C) Trend Micro Inc.
OriginalFilename: 7zsfx.exe
PrivateBuild: Build 1366 - 7/29/2009
ProductName: Trend Micro Internet Security
ProductVersion: 17.50
SpecialBuild: 1366
Translation: 0x0409 0x04e4

Trojan:Win32/Rimecud!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.8841
FireEyeGeneric.mg.7c8dad0b3881ce96
CAT-QuickHealTrojan.Rimecud.AA
SkyhighW32/Rimecud.gen.dq
McAfeeW32/Rimecud.gen.dq
MalwarebytesTrojan.Rimecud
ZillyaTrojan.Kryptik.Win32.947084
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0040f06e1 )
AlibabaTrojan:Win32/Rimecud.6b86cc92
K7GWTrojan ( 0040f06e1 )
Cybereasonmalicious.aaaad4
ArcabitTrojan.Symmi.D2289
BitDefenderThetaGen:NN.ZexaF.36680.hq0@a06aGPji
SymantecW32.Pilleuz!gen37
ESET-NOD32a variant of Win32/Kryptik.ASED
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.8841
NANO-AntivirusTrojan.Win32.Autoruner.crnwfc
AvastWin32:Sality [Inf]
TencentWin32.Trojan.Generic.Kflw
SophosTroj/Rimecud-DG
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLW.Autoruner.44048
VIPREGen:Variant.Symmi.8841
TrendMicroWORM_PALEVO.SMBX
EmsisoftGen:Variant.Symmi.8841 (B)
IkarusVirus.Win32.Cryptor
JiangminPack.Mal.AntiVM.a
WebrootW32.InfoStealer.Zeus
VaristW32/Palevo.L.gen!Eldorado
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.Kryptik.APQL@4sr194
MicrosoftTrojan:Win32/Rimecud!pz
ViRobotWorm.Win32.A.P2P-Palevo.122880.BT
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Symmi.8841
GoogleDetected
AhnLab-V3Win-Trojan/Fakeav18.Gen
VBA32BScope.Malware-Cryptor.2712
ALYacGen:Variant.Symmi.8841
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_PALEVO.SMBX
RisingTrojan.Generic!8.C3 (TFE:5:aam5lSCtjzT)
YandexTrojan.GenAsa!uFll1PEKqCA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Palevo.MATH!worm
AVGWin32:Sality [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Rimecud!pz?

Trojan:Win32/Rimecud!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment