Trojan

What is “AIT:Trojan.Nymeria.3704”?

Malware Removal

The AIT:Trojan.Nymeria.3704 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.3704 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality

How to determine AIT:Trojan.Nymeria.3704?


File Info:

name: 64C4AB27C51EB89FFAA8.mlw
path: /opt/CAPEv2/storage/binaries/ade8fad03d108a33e1cacc37422b2771cffec0b4d3699807ea87ae87527a3ece
crc32: 212559BB
md5: 64c4ab27c51eb89ffaa8a56a93297e81
sha1: 3a00f90bca1f45c9820ccf215cac0a2aa3333715
sha256: ade8fad03d108a33e1cacc37422b2771cffec0b4d3699807ea87ae87527a3ece
sha512: fb4d961652d9917c5f261325feb8d02a565de1627a265bc067c5cbb043f2058da6017ca60c3c2892f897270c96df27c1d5650a95e509517f603cb82dcb2e0e2c
ssdeep: 24576:gAHnh+eWsN3skA4RV1Hom2KXMmHaDLt5:Xh+ZkldoPK8YaDr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175153912B3E1C0E1FEA7A1B3DE55B2F156B86E14C9338C1F1E983D697870161123DA6E
sha3_384: 63ffdfe0778fda724a391b6b0bf498a4d16380627f1086fa700cd8f634c00b4aea24ad3d4711a202642d5a2b865e775a
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2020-03-19 12:10:40

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.3704 also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanAIT:Trojan.Nymeria.3704
FireEyeAIT:Trojan.Nymeria.3704
CAT-QuickHealTrojan.Occamy
McAfeeArtemis!64C4AB27C51E
CylanceUnsafe
AlibabaTrojan:Win32/Generic.6a442fd9
CyrenW32/Trojan.JXYA-6993
TrendMicro-HouseCallTROJ_GEN.R002C0PAB21
Paloaltogeneric.ml
BitDefenderAIT:Trojan.Nymeria.3704
AvastWin32:Malware-gen
Ad-AwareAIT:Trojan.Nymeria.3704
SophosGeneric PUA DK (PUA)
TrendMicroTROJ_GEN.R002C0PAB21
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.dh
EmsisoftAIT:Trojan.Nymeria.3704 (B)
GDataAIT:Trojan.Nymeria.3704 (2x)
WebrootW32.Malware.Gen
MicrosoftTrojan:Win32/Occamy.CAD
APEXMalicious
MAXmalware (ai score=82)
eGambitUnsafe.AI_Score_78%
FortinetW32/Generic_PUA_DK!tr
AVGWin32:Malware-gen
Cybereasonmalicious.7c51eb
PandaTrj/CI.A
MaxSecureTrojan.Malware.103647173.susgen

How to remove AIT:Trojan.Nymeria.3704?

AIT:Trojan.Nymeria.3704 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment