Home Malware Programs Worms W32/Rimecud

W32/Rimecud

Posted: March 9, 2010

Threat Metric

Threat Level: 5/10
Infected PCs: 368
First Seen: November 30, 2010
OS(es) Affected: Windows

W32/Rimecud is a malicious computer worm that can propagate via removal USB drives, Yahoo and MSN Messenger, file-sharing network and network shared resources. W32/Rimecud will inject a malicious code on explorer.exe to run itself on the compromised PC system. Use a proven malware remover to terminate W32/Rimecud when detected.

W32/Rimecud

Aliases

W32/Autorun.JLR [Panda]W32/Injector.HMH!tr [Fortinet]WORM_KOLAB.SMF [TrendMicro]Mal/EncPk-ACW [Sophos]Trojan [K7AntiVirus]Trojan.Refroso.ndx.n4 [CAT-QuickHeal]Trj/Zlob.KH [Panda]W32/CodecPack.KOH!tr.dldr [Fortinet]Win32/Palevo.worm.251911.B [AhnLab-V3]Win32/ASuspect.HAEGG [eTrust-Vet]TR/Injector.tpc [AntiVir]TrojWare.Win32.Injector.AUS [Comodo]Trojan.Downloader-88636 [ClamAV]Win32.Inject.Wn [eSafe]Win32:Inject-YC [Avast]
More aliases (160)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\RECYCLER\S-1-5-21-8957919621-9968929798-373532296-5470\yv8g67.exe File name: yv8g67.exe
Size: 184.32 KB (184320 bytes)
MD5: 94863eb254c5c4dc9736ead9b94d1972
Detection count: 311
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-8957919621-9968929798-373532296-5470
Group: Malware file
Last Updated: December 1, 2010
C:\RECYCLER\S-1-5-21-8513949848-1107530090-184812709-8748\MsMxEng.exe File name: MsMxEng.exe
Size: 251.91 KB (251911 bytes)
MD5: 28fc457b0869713a2690e41e5609d82c
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-8513949848-1107530090-184812709-8748
Group: Malware file
Last Updated: December 8, 2010
C:\RECYCLER\S-1-5-21-1147362239-3615039444-542527580-2606\MsMxEng.exe File name: MsMxEng.exe
Size: 147.45 KB (147456 bytes)
MD5: c9139d1f65b7f57590ee31d7ba0aa99d
Detection count: 53
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-1147362239-3615039444-542527580-2606
Group: Malware file
Last Updated: December 7, 2010
C:\RECYCLER\S-1-5-21-8134433976-7136411744-016300795-8069\schl.exe File name: schl.exe
Size: 420.35 KB (420352 bytes)
MD5: 4b2cddb2545b9e6c03953a94388ac722
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-8134433976-7136411744-016300795-8069
Group: Malware file
Last Updated: January 2, 2011
C:\RECYCLER\S-1-5-21-5473023079-2123386866-299579093-9768\schl.exe File name: schl.exe
Size: 360.96 KB (360960 bytes)
MD5: 006cffad064beeaddc277c34e9e97b9f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-5473023079-2123386866-299579093-9768
Group: Malware file
Last Updated: February 22, 2013

Related Posts

Loading...