Trojan

Trojan.Nymaim malicious file

Malware Removal

The Trojan.Nymaim is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Nymaim virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Exhibits behavior characteristic of Nymaim malware
  • Zeus P2P (Banking Trojan)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

ocdlaotspa.pw
esgccgm.net
ouespmkmszt.pw
pdsjeumxy.net
pcidhvoucmwq.in
meqghoeuo.pw
ynhjgsrmhsoe.net
ncsind.pw
xbdbdn.in
tlskk.in
wqgch.pw
bwjqclionpk.net
uiayqbirkx.net
yeyfs.net
cslkmk.com
ldsqzfiraqx.in
nhpttaxi.pw
hzwpenhmci.net
garmtp.net
spgzfotugse.net
bcpfht.in
ypzouhjmzr.in
kzkgbvmar.com
nfrbacgwlcnj.pw
enjqj.pw
yhvzrzckkll.in
vixzxxbuv.com
eehnwixjkom.com
fajwyacwooml.net
ihtnuvcfcd.net
ttccplptj.pw
jpbodceznnpf.net
swwbsrcazqu.com
huzwkslo.in
athgdftqlvcw.com
irbozsndl.net
aoamajiwqs.pw
pozidqkm.net
bbbiaqmqg.in
jltwjma.net

How to determine Trojan.Nymaim?


File Info:

crc32: 84ABDA56
md5: 129f81d2e91304a525cdb969e5cd74e0
name: 129F81D2E91304A525CDB969E5CD74E0.mlw
sha1: 710fb818b771a25f7ab04e4e7792fa103c9ebd38
sha256: dcab880f79529b98057f087c24d72468a3d38c9efa1bf5207aeb75f9a2d0f078
sha512: 922c640cb735482a8388c91346c7981b20775f42b8a3ff08b53be3a8cbd5ed2ee2209a72413eb208d1e03c9c483855b043d61145e5b77d288f9f74716e5da0a9
ssdeep: 12288:P8t3EsUEMdXXNK3rsJ65AqdK85suWRazNTPEFHcl6oKE4TRye:P8t3Es0orsRqdY8VPEFroKEMEe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Nymaim also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CQWS
FireEyeGeneric.mg.129f81d2e91304a5
CAT-QuickHealRansom.Cerber.ZZ4
ALYacTrojan.Agent.CQWS
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0051aaa01 )
BitDefenderTrojan.Agent.CQWS
K7GWTrojan ( 0051aaa01 )
Cybereasonmalicious.2e9130
BitDefenderThetaGen:NN.ZexaF.34804.MuW@aCQHAEb
CyrenW32/S-02235887!Eldorado
SymantecPacked.Generic.493
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Banker.Win32.GozNym.pef
NANO-AntivirusTrojan.Win32.Kryptik.evfwdl
AegisLabTrojan.Win32.Refinka.4!c
RisingTrojan.Kryptik!1.AE8F (CLASSIC)
Ad-AwareTrojan.Agent.CQWS
TACHYONTrojan/W32.Refinka.626688.AT
EmsisoftTrojan.Agent.CQWS (B)
ComodoTrojWare.Win32.Crypt.C@7vajd0
F-SecureHeuristic.HEUR/AGEN.1111254
DrWebTrojan.Inject2.63739
ZillyaTrojan.FakeAV.Win32.335786
TrendMicroTROJ_KRYPTIK_GK270081.UVPM
McAfee-GW-EditionBehavesLike.Win32.Dropper.jc
SophosMal/Generic-S + Mal/Elenoocka-E
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Refinka.aip
AviraHEUR/AGEN.1111254
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojanDownloader:Win32/Nymaim.K
ArcabitTrojan.Agent.CQWS
ZoneAlarmHEUR:Trojan-Banker.Win32.GozNym.pef
GDataTrojan.Agent.CQWS
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Nymaim.R214335
Acronissuspicious
McAfeeTrojan-FOIZ!129F81D2E913
MAXmalware (ai score=100)
VBA32Trojan.FakeAv
MalwarebytesTrojan.Nymaim
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.GCCF
TrendMicro-HouseCallTROJ_KRYPTIK_GK270081.UVPM
TencentMalware.Win32.Gencirc.10b7a265
YandexTrojan.GenAsa!L1gbhBczgkU
IkarusTrojan-Downloader.Win32.Nymaim
eGambitUnsafe.AI_Score_95%
FortinetW32/Kryptik.GKMB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.297

How to remove Trojan.Nymaim?

Trojan.Nymaim removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment