Trojan

AIT:Trojan.Nymeria.3426 (B) removal instruction

Malware Removal

The AIT:Trojan.Nymeria.3426 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.3426 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Attempts to masquerade or mimic a legitimate process or file name
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

How to determine AIT:Trojan.Nymeria.3426 (B)?


File Info:

name: B165C1B5E8554E052645.mlw
path: /opt/CAPEv2/storage/binaries/d45cbdc807299352708f129ac452397b172f6f2b4c2816db08a8a1d1f061251d
crc32: 756A750E
md5: b165c1b5e8554e05264531efadac4bc9
sha1: b38cf431048f6c6a604900dd5a40ca8d09c5614e
sha256: d45cbdc807299352708f129ac452397b172f6f2b4c2816db08a8a1d1f061251d
sha512: 256f3a8ac7ad6bf18d8855e594bed7239394c5e7ccbce8c0c630562c4bfba47690c34503bdb56b48cd5e0a6591a965b40dd610a9460227c164e7a815f6960ce6
ssdeep: 12288:46Wq4aaE6KwyF5L0Y2D1PqL5VtQcrhPHor:OthEVaPqLVU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1329401D1F38CAD84E62026F204CE29B2C3696F766320933B601565E7A9AD1E3517F71F
sha3_384: acf1eeb876061e035211b2d69b418a951088107a96e2d2ac2330d6f7b3fdf5ae44d0c764b99e023fad3ea581e0ba4cc5
ep_bytes: 60be003048008dbe00e0f7ff57eb0b90
timestamp: 2012-01-29 21:32:28

Version Info:

FileVersion: 0.0.0.0
Comments: File folder
FileDescription: File folder
LegalCopyright: Microsoft Corporation
Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.3426 (B) also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.IRC.Bot.4300
MicroWorld-eScanAIT:Trojan.Nymeria.3426
FireEyeAIT:Trojan.Nymeria.3426
McAfeeTrojan-AitInject.B
CylanceUnsafe
VIPREPacker.NSAnti.Gen (v)
K7AntiVirusTrojan ( 700000111 )
BitDefenderAIT:Trojan.Nymeria.3426
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaAI:Packer.FCE2514219
VirITTrojan.Win32.Generic.ANOP
CyrenW32/AutoIt.TI.gen!Eldorado
SymantecAUT.Heuristic!gen10
ESET-NOD32a variant of Win32/Autoit.OH
KasperskyTrojan.Win32.Autoit.aza
AvastAutoIt:Agent-DP [Trj]
RisingDropper.Pistolar/Autoit!1.A603 (CLASSIC)
Ad-AwareAIT:Trojan.Nymeria.3426
SophosML/PE-A
BaiduAutoIt.Worm.Agent.a
ZillyaTrojan.AutoIT.Win32.25756
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
EmsisoftAIT:Trojan.Nymeria.3426 (B)
IkarusTrojan.Win32.Autoit
GDataAIT:Trojan.Nymeria.3426 (3x)
JiangminTrojan.Autoit.fygp
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASCommon.1AE
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.AutoIt.R159940
VBA32Trojan.Autoit.Wirus
ALYacAIT:Trojan.Nymeria.3426
MAXmalware (ai score=83)
MalwarebytesTrojan.Dropper.AutoIt
APEXMalicious
TencentMalware.Win32.Gencirc.11c04260
MaxSecureTrojan.Autoit.AZA
FortinetAutoIt/Agent.OH!worm
AVGAutoIt:Agent-DP [Trj]
Cybereasonmalicious.5e8554

How to remove AIT:Trojan.Nymeria.3426 (B)?

AIT:Trojan.Nymeria.3426 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment