Worm

Worm.Rimecud.Gen removal guide

Malware Removal

The Worm.Rimecud.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Rimecud.Gen virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Creates a copy of itself

How to determine Worm.Rimecud.Gen?


File Info:

name: D9479F9C9F821F0F2627.mlw
path: /opt/CAPEv2/storage/binaries/e0df5f769b76e0ab12512d23e5ad8edfc8492ea8e2f22b73fd6b11d6e3feae36
crc32: CF3C9BFF
md5: d9479f9c9f821f0f26279ec54eddb158
sha1: c88fadb74e1e9da47e7c8cda8ebd37de0e9c462d
sha256: e0df5f769b76e0ab12512d23e5ad8edfc8492ea8e2f22b73fd6b11d6e3feae36
sha512: 2fad291b30475e1112fe899008c5da523389bb264c032a65bbdf6be17daef3735978cc77c8f47f8d23c23d69d337748bc63b69856c6eb339b6ba49900ad04a0d
ssdeep: 1536:GX+SZjfLlZaHGUdzS8kltsHlJm/XQUSAMPXe/Kd19YjG3mVQ0:GOSZRXUtaH8+2AeXeCdwC2Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C93F10AB427C669DA7947F0DAA26CF2C0E35C51CA32549F0B947DAE7D7120DF62C20E
sha3_384: 65296712478fad54046a75ec6d67c189ed6a0c8e71fd5afaff4af4266858966abc30f2867c88b33859f3b611c5fbb0ec
ep_bytes: 8bff558bec81ecb800000068d0114000
timestamp: 2010-03-11 11:29:55

Version Info:

0: [No Data]

Worm.Rimecud.Gen also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.44048
MicroWorld-eScanGen:Variant.Rimecud.7
FireEyeGeneric.mg.d9479f9c9f821f0f
ALYacGen:Variant.Rimecud.7
MalwarebytesWorm.Rimecud.Gen
VIPREGen:Variant.Rimecud.7
K7AntiVirusTrojan ( 00548af81 )
K7GWTrojan ( 00548af81 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34786.fmW@a428L7ei
CyrenW32/Rimecud.T.gen!Eldorado
SymantecW32.Pilleuz!gen32
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.RTT
TrendMicro-HouseCallWORM_PALEVO.SMXI
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Rimecud.7
NANO-AntivirusTrojan.Win32.Autoruner.wfhpg
AvastWin32:Crypt-RKV [Trj]
RisingMalware.FakeFolder/ICON!1.6ABF (CLASSIC)
Ad-AwareGen:Variant.Rimecud.7
SophosMal/Generic-R + Mal/Palevo-A
ComodoTrojWare.Win32.Kryptik.RTT@4l2com
F-SecureTrojan.TR/Crypt.XPACK.Gen5
ZillyaTrojan.Kryptik.Win32.267353
TrendMicroWORM_PALEVO.SMXI
McAfee-GW-EditionW32/Rimecud.gen.cg
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Rimecud.7 (B)
IkarusP2P-Worm.Win32.Palevo
GDataGen:Variant.Rimecud.7
JiangminTrojan/Generic.aihhm
AviraTR/Crypt.XPACK.Gen5
Antiy-AVLTrojan/Win32.Unknown
ArcabitTrojan.Rimecud.7
SUPERAntiSpywareTrojan.Agent/Gen-Folden
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Rimecud.R10277
McAfeeW32/Rimecud.gen.cg
VBA32BScope.P2P-Worm.Palevo
CylanceUnsafe
APEXMalicious
YandexTrojan.GenAsa!YXuxG0NqSTs
MAXmalware (ai score=82)
FortinetW32/Sasfis.G!tr
AVGWin32:Crypt-RKV [Trj]
Cybereasonmalicious.c9f821
PandaGeneric Malware

How to remove Worm.Rimecud.Gen?

Worm.Rimecud.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment