Trojan

About “AIT:Trojan.Nymeria.353” infection

Malware Removal

The AIT:Trojan.Nymeria.353 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.353 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
paste.ee

How to determine AIT:Trojan.Nymeria.353?


File Info:

crc32: 2CF53A22
md5: 2a17aeadc7a69934a7c7da4edc905aa7
name: 2A17AEADC7A69934A7C7DA4EDC905AA7.mlw
sha1: 8e2c2038039dc56e3460c3886c73cdf9522cfeda
sha256: 23b9a33f29cb2e5631fb4f9e0afa99c35d6d808cbc3a0456a89561ca07cd9d2f
sha512: fc7647fd8359222425c4c87c032edea87eba49aa53911de619988c366cf3d154782b83c0269bd33393dd4eedead1117cf5d4d9ee77f66a21709396d5923e9711
ssdeep: 24576:E4lavt0LkLL9IMixoEgeaQ0+kZTkzDnk0KleDR9h03Tq9MmCS:Tkwkn9IMHeaQahqk0Kli9h0jaPCS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.353 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005642691 )
LionicTrojan.Script.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Nanocore.15
CynetMalicious (score: 100)
ALYacAIT:Trojan.Nymeria.353
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Script/Injector.199c4fc6
K7GWTrojan ( 005642691 )
Cybereasonmalicious.dc7a69
CyrenW32/Agent.AFI.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.Autoit.DEJ
APEXMalicious
AvastFileRepMalware
KasperskyUDS:Trojan.Win32.Inject.sb
BitDefenderAIT:Trojan.Nymeria.353
NANO-AntivirusTrojan.Win32.Nanocore.fhqtwj
MicroWorld-eScanAIT:Trojan.Nymeria.353
TencentWin32.Trojan.Nymeria.Hqbv
Ad-AwareAIT:Trojan.Nymeria.353
SophosMal/Generic-S
ComodoMalware@#1kegkadr3q41m
BitDefenderThetaAI:Packer.8E100A4A16
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.2a17aeadc7a69934
EmsisoftAIT:Trojan.Nymeria.353 (B)
AviraHEUR/AGEN.1100190
eGambitUnsafe.AI_Score_93%
MicrosoftTrojan:Win32/Occamy.C23
ArcabitAIT:Trojan.Nymeria.353
GDataAIT:Trojan.Nymeria.353 (2x)
McAfeeArtemis!2A17AEADC7A6
MAXmalware (ai score=100)
MalwarebytesBackdoor.Bladabindi
IkarusTrojan.Win32.Tiny
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Script.DEJ!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove AIT:Trojan.Nymeria.353?

AIT:Trojan.Nymeria.353 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment