Trojan

AIT:Trojan.Nymeria.3680 removal instruction

Malware Removal

The AIT:Trojan.Nymeria.3680 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.3680 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Attempts to modify Internet Explorer’s start page
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses suspicious command line tools or Windows utilities

How to determine AIT:Trojan.Nymeria.3680?


File Info:

name: 12F39027087CBB7726F4.mlw
path: /opt/CAPEv2/storage/binaries/57e5ab92c502304cf8434f92ed78d29df72ca1cbb81bec5e0d27f870830e04cb
crc32: 230AC982
md5: 12f39027087cbb7726f469492f640bcd
sha1: 90298b0af0e0e20fd938ddb7652d136199e1e340
sha256: 57e5ab92c502304cf8434f92ed78d29df72ca1cbb81bec5e0d27f870830e04cb
sha512: 1d33c7d10f11db8cd0fb48fe50697f0e223f757bbcfa5044073d7159c49d9998bb2b71ec9f0288869c66150813916197297e8f981ca5ccd6d2e2f73e8669b1a4
ssdeep: 12288:Z0X0KOnD/voMRQlNmrbhod2hiRAXQNs44BF4lICxpV8qKump+7XfwDwAS+Mb:aX0hD34ShYVRyg0Ap2qzXoDwLb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163C42309B122C02BFA855C376427B647113F18E7545266ED8CA29E8FBC707C2A0F6F5B
sha3_384: 1dde58e009a3be53c3383eba67490ffc1e5e10ec641f173c34a9fff963623f1ca6a3aacdcfb35cbf9138031acd0c06a3
ep_bytes: 60be000048008dbe0010f8ff57eb0b90
timestamp: 2021-09-19 01:43:38

Version Info:

FileVersion: 17.3.6318.405
Comments: http://www.autoitscript.com/autoit3/
FileDescription: 系统保护!~如有误报,请保留!~
ProductVersion: 1.0
LegalCopyright: https://www.baidu.com/
Translation: 0x0804 0x04b0

AIT:Trojan.Nymeria.3680 also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.StartPage.1!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.3680
FireEyeGeneric.mg.12f39027087cbb77
McAfeeArtemis!12F39027087C
CylanceUnsafe
SangforTrojan.Win32.Agent.V3kj
AlibabaRiskWare:Win32/StartPage.e300cc95
Cybereasonmalicious.7087cb
tehtrisGeneric.Malware
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:RiskTool.Win32.StartPage.qzn
BitDefenderAIT:Trojan.Nymeria.3680
TencentMalware.Win32.Gencirc.115e2b1d
Ad-AwareAIT:Trojan.Nymeria.3680
VIPREAIT:Trojan.Nymeria.3680
Trapminemalicious.high.ml.score
EmsisoftAIT:Trojan.Nymeria.3680 (B)
GDataAIT:Trojan.Nymeria.3680 (2x)
Antiy-AVLTrojan/Generic.ASMalwS.21C
ArcabitAIT:Trojan.Nymeria.DE60 [many]
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
ALYacAIT:Trojan.Nymeria.3680
MAXmalware (ai score=84)
VBA32Trojan.Autoit.F
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R002H09K322
RisingHacktool.StartPage!8.BCD9 (CLOUD)
IkarusTrojan.Win32.Injector
FortinetW32/PossibleThreat

How to remove AIT:Trojan.Nymeria.3680?

AIT:Trojan.Nymeria.3680 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment