Trojan

AIT:Trojan.Nymeria.1877 removal tips

Malware Removal

The AIT:Trojan.Nymeria.1877 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.1877 virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine AIT:Trojan.Nymeria.1877?


File Info:

name: FB7F4D23EE7A1AD021A9.mlw
path: /opt/CAPEv2/storage/binaries/79db1fd957febde2eed7586561705614cf5c0b5f79fd40c89af9c3eefc2cfbe6
crc32: 7A345809
md5: fb7f4d23ee7a1ad021a9e458afdeb1f9
sha1: 9c7565783446049833c1f3168903e54ca6aaa346
sha256: 79db1fd957febde2eed7586561705614cf5c0b5f79fd40c89af9c3eefc2cfbe6
sha512: 1da42b78c9e5e701e643a03076fdaeda2f4a5cf5b267f5b7444fa406e63d1a7748b357743d0d3802f7acc78c45c4e9ad447fff704b0c268efe8b7df1e2b73e6c
ssdeep: 24576:4KACnbzhKcNKrpgvAkaRy5GzUrP2XgI3Y37VUIUcp8lQ:/bzDKtgIkaRyP7m92
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14365D052A3DD82D1CE326273BD2977426F7BE8314630B9572F941C7CAE231B1524DAA3
sha3_384: 39e5465e8dd1b37fa1e0538c3b2fd47064cf3b1ebe3fa670fb4aa343ca79027e7b475dff2a42cd77a78723c5e44dce64
ep_bytes: e8b8d00000e97ffeffffcccccccccccc
timestamp: 2019-01-21 07:12:29

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.1877 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.1877
FireEyeGeneric.mg.fb7f4d23ee7a1ad0
ALYacAIT:Trojan.Nymeria.1877
CylanceUnsafe
SangforVirus.Win32.Save.a
Cybereasonmalicious.3ee7a1
CyrenW32/FakeDoc.I.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.Autoit.DVU
APEXMalicious
ClamAVWin.Malware.Nymeria-6931790-0
KasperskyUDS:Trojan.Script.Generic
BitDefenderAIT:Trojan.Nymeria.1877
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10b3f1dc
Ad-AwareAIT:Trojan.Nymeria.1877
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.th
SophosML/PE-A + Mal/AuItInj-A
GDataAIT:Trojan.Nymeria.1877 (2x)
AviraHEUR/AGEN.1245857
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Win-Trojan/AutoInj.Exp
McAfeeTrojan-AitInject.ak
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
RisingTrojan.Obfus/Autoit!1.BB81 (CLASSIC)
IkarusTrojan.AutoIT.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Injector.DVU!tr
BitDefenderThetaAI:Packer.E887835717
AVGWin32:Trojan-gen
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (W)

How to remove AIT:Trojan.Nymeria.1877?

AIT:Trojan.Nymeria.1877 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment