Trojan

How to remove “Trojan.MSIL.Nymaim”?

Malware Removal

The Trojan.MSIL.Nymaim is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MSIL.Nymaim virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the zgRAT malware family
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan.MSIL.Nymaim?


File Info:

name: 3BB4F254CDB132088723.mlw
path: /opt/CAPEv2/storage/binaries/34d5c36d1b169ab6508408383195ad9b9a44c2fb378835789168978b369f0eeb
crc32: D5B44C8C
md5: 3bb4f254cdb132088723f53d382f4dff
sha1: dd16139fb0f68956613e76a480426e0f3b7bdef7
sha256: 34d5c36d1b169ab6508408383195ad9b9a44c2fb378835789168978b369f0eeb
sha512: 4be8e8df056d30c2570758b5ccfd63bfe18010dc5b4b5d1e839b505c328540733c2beda5b4183bc580a1f96ae44c51f86c4dfd88e04fd6a99ee50d630d74b790
ssdeep: 98304:r4/bF/WOAhDcY58TEY11bcOok+f2pigMH6M9lDrmmDigUAnpQ:ro8hDN5fYzcOokNhMH6MTrpDK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E1668D06BF95DA17C1186B33C6D7041443B5ED826763EB0F36D6336A1A133BE4D8A6CA
sha3_384: dd8f3f9669f84e2aabebf553685ee166525fc4d8d1d4c11d2b21bae0dd98901400aff5e937db93ec5bec561647af7ac6
ep_bytes: ff250020400000000000000000000000
timestamp: 2069-05-23 01:13:44

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: statistical_data_taken_for_the_year
FileVersion: 1.0.0.1
InternalName: statistical_data_taken_for_the_year.exe
LegalCopyright: Copyright © 2023
LegalTrademarks:
OriginalFilename: statistical_data_taken_for_the_year.exe
ProductName: statistical_data_taken_for_the_year
ProductVersion: 1.0.0.1
Assembly Version: 1.0.0.1

Trojan.MSIL.Nymaim also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Nymaim.4!c
MicroWorld-eScanTrojan.GenericKD.71171647
SkyhighArtemis!Trojan
Cylanceunsafe
AlibabaTrojan:MSIL/Kryptik.6613fa23
ArcabitTrojan.Generic.D43DFE3F
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of MSIL/Kryptik.AJDT
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.Nymaim.gen
BitDefenderTrojan.GenericKD.71171647
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Trojan.FalseSign.Cdhl
EmsisoftTrojan.GenericKD.71171647 (B)
F-SecureTrojan.TR/Kryptik.sukja
DrWebTrojan.PackedNET.2400
VIPRETrojan.GenericKD.71171647
IkarusTrojan.MSIL.Crypt
WebrootW32.Malware.Gen
VaristW32/MSIL_Kryptik.KIT.gen!Eldorado
AviraTR/Kryptik.sukja
KingsoftMSIL.Trojan.Nymaim.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan.MSIL.Nymaim.gen
GDataTrojan.GenericKD.71171647
GoogleDetected
McAfeeArtemis!3BB4F254CDB1
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTROJ_GEN.R002H0DAA24
RisingTrojan.Kryptik!8.8 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetMSIL/Kryptik.AJDT!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.MSIL.Nymaim?

Trojan.MSIL.Nymaim removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment