Trojan

Should I remove “AIT:Trojan.Nymeria.190 (B)”?

Malware Removal

The AIT:Trojan.Nymeria.190 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.190 (B) virus can do?

  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

ts3suchti.ddns.net

How to determine AIT:Trojan.Nymeria.190 (B)?


File Info:

crc32: 65F02211
md5: 3cca71e0cfc7b1f59f340a3ecf432eac
name: 3CCA71E0CFC7B1F59F340A3ECF432EAC.mlw
sha1: 3bc59cff3a877645b105710871a1bc46eb143cb0
sha256: 214b83cfa8bbba4e193e693fd39d5695b07bbc215723b3e16951ecdd79eaad28
sha512: 299d309736f77915759408ccb3bd888cb0d7e0532e1d6fed09f74b79225d7540bc8123c83b4c921ea4f2c73f58d5ecf5471b6f32592ebd7ee549cc84a9250190
ssdeep: 12288:16Wq4aaE6KwyF5L0Y2D1PqLnynQ1A1+FM6L13n4tvF5ppRF9X0ELwiP:DthEVaPqLyQiaM6t4tvFn/F9qiP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.190 (B) also known as:

K7AntiVirusTrojan ( 004640141 )
LionicTrojan.Win32.Autoit.b!c
Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Bot.5409
MicroWorld-eScanAIT:Trojan.Nymeria.190
ALYacAIT:Trojan.Nymeria.190
MalwarebytesMalware.AI.1578344995
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 004640141 )
Cybereasonmalicious.0cfc7b
BaiduWin32.Trojan-PSW.Autoit.c
CyrenW32/Trojan.NWKC-1111
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
AvastAutoIt:Injector-IM [Trj]
ClamAVWin.Malware.Autoit-6912463-0
KasperskyTrojan-Dropper.Win32.Autoit.abceqi
BitDefenderAIT:Trojan.Nymeria.190
NANO-AntivirusTrojan.Win32.Autoit.fekwen
TencentWin32.Trojan-dropper.Autoit.Lnyo
Ad-AwareAIT:Trojan.Nymeria.190
SophosMal/Generic-S
ComodoMalware@#1d6q30x23xh7y
BitDefenderThetaAI:Packer.B828C09216
McAfee-GW-EditionBehavesLike.Win32.Spyware.bc
FireEyeAIT:Trojan.Nymeria.190
EmsisoftAIT:Trojan.Nymeria.190 (B)
JiangminTrojanDropper.Autoit.bzm
AviraHEUR/AGEN.1119170
eGambitUnsafe.AI_Score_95%
MicrosoftTrojan:Win32/Occamy.C
GDataAIT:Trojan.Nymeria.190 (3x)
McAfeeGeneric.dvg
MAXmalware (ai score=98)
VBA32Trojan-Downloader.Autoit.gen
RisingBackdoor.888Rat/Autoit!1.C8E3 (CLASSIC)
IkarusTrojan.Autoit
FortinetW32/Autoit.CE!tr
AVGAutoIt:Injector-IM [Trj]
Paloaltogeneric.ml

How to remove AIT:Trojan.Nymeria.190 (B)?

AIT:Trojan.Nymeria.190 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment