Trojan

TrojanDownloader:Win32/Nymaim!rfn removal guide

Malware Removal

The TrojanDownloader:Win32/Nymaim!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Nymaim!rfn virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Nymaim!rfn?


File Info:

crc32: 62AFCD40
md5: 9b023fccef2aaffa4ce6d0c48f4b313f
name: 9B023FCCEF2AAFFA4CE6D0C48F4B313F.mlw
sha1: f3eb4ece7f052adf3d53798d6eedfe2b99bb9c6d
sha256: bdc5e197ac4e916bde15cb37ea472e5621cecf1585c8b7634b3181351d8970ab
sha512: c479e9488e1e0ec4465c5367c7cabb92544fd1e46f81c016587bb1d72d3d8d7c15e1350f1e5d1a99be159530b6fa13c7fcb32078f1f7547b4e197e00c405297d
ssdeep: 24576:Aub5YaDVNa/uQtWzkM2EveiTe5+t258gw:9V4uJzkrIk8Q5O
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Nymaim!rfn also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Nymaim.180
MicroWorld-eScanTrojan.Agent.CPGC
FireEyeGeneric.mg.9b023fccef2aaffa
CAT-QuickHealTrojan.Dtae
ALYacTrojan.Agent.CPGC
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
K7AntiVirusTrojan ( 0052ef101 )
BitDefenderTrojan.Agent.CPGC
K7GWTrojan ( 0051aa431 )
Cybereasonmalicious.cef2aa
BitDefenderThetaAI:Packer.9B24C6A621
CyrenW32/Nymaim.CJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDownloader:Win32/Injector.a509db95
NANO-AntivirusTrojan.Win32.Inject.euozyt
TencentMalware.Win32.Gencirc.10ba6495
Ad-AwareTrojan.Agent.CPGC
SophosMal/Generic-S
ComodoMalware@#2ppjb8jr5je3a
F-SecureHeuristic.HEUR/AGEN.1117620
TrendMicroTROJ_NYMAIM.SMR2
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
EmsisoftTrojan.Agent.CPGC (B)
IkarusTrojan.Crypt.XPACK
GDataTrojan.Agent.CPGC
JiangminTrojan.Regsup.zx
AviraHEUR/AGEN.1117620
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Agent.CPGC
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDownloader:Win32/Nymaim!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C2255361
Acronissuspicious
McAfeeTrojan-FMZG!9B023FCCEF2A
VBA32Trojan.Regsup
MalwarebytesMalware.AI.4294741553
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DTAE
TrendMicro-HouseCallTROJ_NYMAIM.SMR2
RisingTrojan.Generic@ML.97 (RDML:nBzEy0JbIInIVVwfUlaL2w)
YandexTrojan.Regsup!IILuy2i7hRk
SentinelOneStatic AI – Malicious PE – Downloader
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FXUE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.839

How to remove TrojanDownloader:Win32/Nymaim!rfn?

TrojanDownloader:Win32/Nymaim!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment