Malware

How to remove “Generic.Nymaim.E.EE61D852”?

Malware Removal

The Generic.Nymaim.E.EE61D852 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Nymaim.E.EE61D852 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Attempts to interact with an Alternate Data Stream (ADS)

Related domains:

microsoft-com.mail.protection.outlook.com

How to determine Generic.Nymaim.E.EE61D852?


File Info:

crc32: 908B5A16
md5: 9422a69f21f529aef1a14f47a0179b4b
name: 9422A69F21F529AEF1A14F47A0179B4B.mlw
sha1: 500bc88fba4fa55cea1714858369ac731d3a2c1c
sha256: 5e12608d9feadccf6ad559002a268b19a68e27d632a5c7c1581dec76d3502124
sha512: 27ddf38674db57683715d2e4e5ee81ebe3861f463b35f75f60f36d1f07e464729c1c1c9ceb5df2152de77f574fca78fb9c8607b9eda9c182ac81547f5135919a
ssdeep: 98304:itttttttttttttttttttttttttttttttttttttttttttttttttttttttttttttt:
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Generic.Nymaim.E.EE61D852 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.47274
MicroWorld-eScanGeneric.Nymaim.E.EE61D852
FireEyeGeneric.mg.9422a69f21f529ae
CAT-QuickHealBackdoor.Tofsee.DE4
Qihoo-360HEUR/QVM20.1.3FBB.Malware.Gen
McAfeePacked-VH!9422A69F21F5
CylanceUnsafe
VIPRELookslike.Win32.Sirefef.wa (v)
SangforMalware
BitDefenderGeneric.Nymaim.E.EE61D852
CrowdStrikewin/malicious_confidence_100% (D)
TrendMicroRansom_CERBER.SMALY0A
BitDefenderThetaGen:NN.ZexaF.34634.@tW@aS6QMQk
CyrenW32/Kryptik.CAC.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Malware.Poison-7003033-0
KasperskyHEUR:Trojan.Win32.Generic
TencentMalware.Win32.Gencirc.10b6bf0e
Ad-AwareGeneric.Nymaim.E.EE61D852
SophosMal/Elenoocka-E
ComodoTrojWare.Win32.Ransom.Lukitos.B@7f84mw
InvinceaML/PE-A + Mal/Elenoocka-E
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
EmsisoftGeneric.Nymaim.E.EE61D852 (B)
IkarusTrojan.Win32.Lebag
JiangminTrojan.Generic.glrua
AviraTR/Crypt.XPACK.Gen8
MicrosoftTrojan:Win32/Wacatac.C!ml
GridinsoftTrojan.Heur!.02012021
ArcabitGeneric.Nymaim.E.EE61D852
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGeneric.Nymaim.E.EE61D852
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Poison.R213859
Acronissuspicious
VBA32Trojan.FakeAV.01657
ALYacGeneric.Nymaim.E.EE61D852
MAXmalware (ai score=82)
ESET-NOD32a variant of Win32/Kryptik.FZSQ
TrendMicro-HouseCallRansom_CERBER.SMALY0A
RisingTrojan.Kryptik!1.B3B3 (CLASSIC)
YandexTrojan.GenAsa!V9AcYpoWSAQ
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.CQXJ!tr
AVGFileRepMalware
Cybereasonmalicious.f21f52
MaxSecureTrojan.Malware.7164915.susgen

How to remove Generic.Nymaim.E.EE61D852?

Generic.Nymaim.E.EE61D852 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment