Trojan

TrojanDownloader:Win32/Nymaim.K (file analysis)

Malware Removal

The TrojanDownloader:Win32/Nymaim.K is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Nymaim.K virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Nymaim.K?


File Info:

crc32: 5A95692B
md5: 023bfdbdde9e5974402a2cf281dde2ab
name: Faktura_VAT_8aa9a3861c744fd9adfa075824a01c312.exe
sha1: c0613266911eb71f7affb08feda85b134a4a084c
sha256: e5b69aead2351bb20a15e009937a41cf8bea383de044f99cda1b079245c2db34
sha512: 1df5a2f667754de791bbecffc1bda708c7f5ee00b511cc028e7ab3c1ab282a8365340e8b09bd94ca6d4d126ae58acfd40ad73552c0f59acb05118b1de755ecfd
ssdeep: 12288:xuG11UMV/7aP8Rwa9/uUQH0zv92ZSe1VVT59lp6/RZNIg:xh1UY/7aP8RwG/unHs2ZS+TN9/6/RZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Nymaim.K also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.30556268
FireEyeTrojan.GenericKD.30556268
ALYacTrojan.GenericKD.30556268
MalwarebytesTrojan.Nymaim
SangforMalware
K7AntiVirusTrojan ( 0052d0ae1 )
AlibabaTrojanDownloader:Win32/Nymaim.886e29b6
K7GWTrojan ( 0052d0ae1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34130.4qW@aSoFDspi
SymantecPacked.Generic.493
ESET-NOD32a variant of Win32/Kryptik.GFGU
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.30556268
NANO-AntivirusTrojan.Win32.Nymaim.ezpbqb
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Kryptik!1.B18A (CLOUD)
Ad-AwareTrojan.GenericKD.30556268
SophosMal/Elenoocka-G
ComodoTrojWare.Win32.Crypt.C@7vajd0
F-SecureTrojan.TR/Crypt.XPACK.Gen8
DrWebTrojan.Nymaim.218
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.30556268 (B)
GDataWin32.Trojan.Kryptik.KJ
AviraTR/Crypt.XPACK.Gen8
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojanDownloader:Win32/Nymaim.K
Endgamemalicious (high confidence)
AhnLab-V3Trojan/Win32.Agent.R224588
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
Acronissuspicious
McAfeeGenericRXEQ-NH!023BFDBDDE9E
VBA32BScope.Trojan.Nymaim
TrendMicro-HouseCallTrojan.Win32.ELENOOKA.SM.hp
TencentWin32.Trojan.Generic.Bxr
YandexTrojan.Nymaim!RRjc1uVrKgE
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_85%
FortinetW32/Kryptik.CQXJ!tr
Cybereasonmalicious.dde9e5
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.5a2

How to remove TrojanDownloader:Win32/Nymaim.K?

TrojanDownloader:Win32/Nymaim.K removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment