TROJ_RIMECUD.AJL
Posted: December 11, 2012
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
| Threat Level: | 9/10 |
|---|---|
| Infected PCs: | 14 |
| First Seen: | December 11, 2012 |
|---|---|
| OS(es) Affected: | Windows |
TROJ_RIMECUD.AJL is a fake Trend Micro PC security component that installs a Bitcoin miner onto the affected PC. Bitcoin miners exploit the resources of infected computers to generate fraudulent e-currency, and coincidentally also may cause significant problems with system performance – particularly for low-end systems. Unsurprisingly, the actual Trend Micro company was quick to identify this threat and defend their own brand name. Distribution points for TROJ_RIMECUD.AJL haven't yet been analyzed, but SpywareRemove.com malware experts stress that TROJ_RIMECUD.AJL, an EXE file, still needs to be launched – either manually or by another PC threat – before TROJ_RIMECUD.AJL can install its payload. Avoiding malicious download sources and acquiring Trend Micro products only from the original sources will help to evade TROJ_RIMECUD.AJL attacks, and removing TROJ_RIMECUD.AJL's payload can, naturally, be done with any good anti-malware product.
The Big Chill that TROJ_RIMECUD.AJL Puts on Digital Money
TROJ_RIMECUD.AJL is disguised (in terms of its associated file information, such as its Description text) as a fake security product or component from Trend Micro, a well-known PC security company. Along with a randomly-generated file name, these details may trick some PC users into thinking that TROJ_RIMECUD.AJL is a legitimate patch or other update-related file from that company, but SpywareRemove.com malware research team has confirmed that TROJ_RIMECUD.AJL's actual purpose is to be a Trojan downloader.
After TROJ_RIMECUD.AJL is launched (either manually or by other malware), TROJ_RIMECUD.AJL opens a fake Svchost.exe process – the name of a normal Windows file – and then installs a second piece of malware that's identified as HKTL_BITCOINMINE. HKTL_BITCOINMINE, a standard Bitcoin miner that uses your computer's RAM, CPU and other resources to generate fake Bitcoins through repetitive functions. SpywareRemove.com malware analysts note that, while these malicious functions take place in the background and will not show obvious symptoms, they may be somewhat detectable due to their resource usage and the side effects (such as poor PC performance, sluggishness and unresponsiveness) that are characteristic of having low system resources.
How You Can Keep Your Computer from Choking on a Cud of TROJ_RIMECUD.AJL
TROJ_RIMECUD.AJL and HKTL_BITCOINMINE, as malware, will try to avoid giving away their real functions or, in the latter's case, even its presence on your computer. SpywareRemove.com malware researchers strongly encourage the usage of anti-malware products for finding or removing TROJ_RIMECUD.AJL, as well as malware related to TROJ_RIMECUD.AJL attacks. Any significant delay in this allows your PC to be exploited for Bitcoin generation and, potentially, other crimes.
TROJ_RIMECUD.AJL is designed to attack Windows computers, and SpywareRemove.com malware researchers have found compatibility with TROJ_RIMECUD.AJL and more than one version of Windows. Different anti-malware programs may detect TROJ_RIMECUD.AJL by one of many aliases, including Trojan.Win32.Rimecud.ag, W32/Rimecud.gen.dp and Trojan:Win32/Rimecud.A.
Since TROJ_RIMECUD.AJL has been confirmed to be distributed in the wild, you also should take suitable measures to protect yourself from possible TROJ_RIMECUD.AJL infections. SpywareRemove.com malware experts consider freeware sites and sites that offer fake security updates to be the most likely infection vectors for TROJ_RIMECUD.AJL, although other means of ingress (such as spam e-mail) also are possible.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:7zsfx.exe
File name: 7zsfx.exeSize: 2.61 MB (2612477 bytes)
MD5: e2440a4e9177e6978af28145b7061c30
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 5, 2013
5ae85393c63653b195067c110e12c665
File name: 5ae85393c63653b195067c110e12c665Size: 19.44 MB (19442941 bytes)
MD5: 5ae85393c63653b195067c110e12c665
Detection count: 64
Group: Malware file
Last Updated: March 5, 2013
8bceab717d74447d8e6f62e3a46f549f
File name: 8bceab717d74447d8e6f62e3a46f549fSize: 98.3 KB (98304 bytes)
MD5: 8bceab717d74447d8e6f62e3a46f549f
Detection count: 57
Group: Malware file
Last Updated: March 5, 2013
file.exe
File name: file.exeSize: 301.05 KB (301056 bytes)
MD5: 8dad47129c2d9b03f38dc4a843620964
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 11, 2016
More files
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.