Trojan

Should I remove “AIT:Trojan.Nymeria.2595”?

Malware Removal

The AIT:Trojan.Nymeria.2595 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.2595 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine AIT:Trojan.Nymeria.2595?


File Info:

name: 39B7AC089B94C51B3420.mlw
path: /opt/CAPEv2/storage/binaries/a269fa9eea7f47e98865225734910adc558b56cf5b57ea25d673507e42e2123e
crc32: 850A7885
md5: 39b7ac089b94c51b342033e3a8c7b991
sha1: 09f7a34d5548b600725653ee4fbb908dac23d3be
sha256: a269fa9eea7f47e98865225734910adc558b56cf5b57ea25d673507e42e2123e
sha512: 4321a4bc1e64770167dc8a81dab613ceb3523c1f55e36884f6bea2e37907907618a5c5dca4ccad0d65787012f63063d5144df8361fd2e0381ee69fd380ebc87c
ssdeep: 24576:TCORWlZcF1yaXUzdT6AM+r2al1NXtgxlKSgkMuxm/bvrQgDG0c4s:+lZi1szYAvqal1NXswS90rQQm4s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F465C01373A18075FFAE86338B5AF221877C3C650233A91F23993D6D6D72171662E663
sha3_384: aa52abd6e9a8fdfdb64db1536d3365e8dc9ec982f62ff34d267d60c2e5bbde073d62534e13b222a29169c6af44f0ed1a
ep_bytes: e8c5d00000e97ffeffffcccccccccccc
timestamp: 2018-07-11 15:09:42

Version Info:

FileVersion: 13.4.0.87
Comments: -
FileDescription: -
ProductVersion: 3.3.15.0
LegalCopyright: -
Translation: 0x040c 0x04b0

AIT:Trojan.Nymeria.2595 also known as:

LionicTrojan.Win32.Nymeria.4!c
MicroWorld-eScanAIT:Trojan.Nymeria.2595
ClamAVWin.Dropper.Autoit-6646809-0
FireEyeAIT:Trojan.Nymeria.2595
SkyhighBehavesLike.Win32.TrojanAitInject.tc
McAfeeArtemis!39B7AC089B94
Cylanceunsafe
APEXMalicious
CynetMalicious (score: 100)
BitDefenderAIT:Trojan.Nymeria.2595
EmsisoftAIT:Trojan.Nymeria.2595 (B)
Trapminemalicious.high.ml.score
GDataAIT:Trojan.Nymeria.2595 (2x)
Kingsoftmalware.kb.a.723
XcitiumApplication.Win32.InstallMetrix.LQL@5qtrlc
ArcabitAIT:Trojan.Nymeria.DA23 [many]
GoogleDetected
ALYacAIT:Trojan.Nymeria.2595
MAXmalware (ai score=85)
VBA32Trojan.Autoit.Wirus
MalwarebytesMachineLearning/Anomalous.96%
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H09GI23
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.214753960.susgen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove AIT:Trojan.Nymeria.2595?

AIT:Trojan.Nymeria.2595 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment