Trojan

AIT:Trojan.Nymeria.4018 (B) removal instruction

Malware Removal

The AIT:Trojan.Nymeria.4018 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.4018 (B) virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine AIT:Trojan.Nymeria.4018 (B)?


File Info:

crc32: B3627469
md5: 0628e3f4439162b3ea35a49ba17e988d
name: 0628E3F4439162B3EA35A49BA17E988D.mlw
sha1: 467de3a3115a73612ec30aebd2cde3b667d99d2b
sha256: 35e6b590a22f9c6b49d3b306d17f1bcf8d2f43e1ed63d3c2faf3b5a5328847a1
sha512: 009a21afeae2118b6afe6f03baabe22d990e4aa64be3043a370fb08bfd6c950bdf0aae0fd6cae0ca93e7a9dc3ac9ff40e90e3fccbc96ebd495e1c3e2645d63c4
ssdeep: 24576:MRmJkcoQricOIQxiZY1WN01ilbuaM6tGkFMYaTTtvFn/F9qip:ZJZoQrbTFZY1WNbbjM6rFgHnj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
FileVersion: 3, 3, 8, 1
FileDescription:
Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.4018 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0048b1441 )
Elasticmalicious (high confidence)
DrWebTrojan.Bankfraud.3628
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.519232
CylanceUnsafe
ZillyaTrojan.AutoIT.Win32.112201
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanBanker:Win32/Lokmwiz.f2e42f11
K7GWTrojan ( 0048b1441 )
Cybereasonmalicious.443916
CyrenW32/Trojan.NWKC-1111
SymantecTrojan.Lodarat
ESET-NOD32multiple detections
APEXMalicious
AvastScript:SNH-gen [Trj]
ClamAVWin.Malware.Autoit-6912463-0
KasperskyTrojan-Dropper.Win32.Autoit.abceqi
BitDefenderAIT:Trojan.Nymeria.4018
NANO-AntivirusTrojan.Win32.Bankfraud.efjtmx
MicroWorld-eScanAIT:Trojan.Nymeria.4018
TencentWin32.Trojan-dropper.Autoit.Dbc
Ad-AwareAIT:Trojan.Nymeria.4018
SophosMal/Generic-S
ComodoMalware@#23iobj6gw3lva
BitDefenderThetaAI:Packer.0DA08E8C16
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Lokmwiz.R002C0CFE21
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.0628e3f4439162b3
EmsisoftAIT:Trojan.Nymeria.4018 (B)
JiangminTrojanDropper.Autoit.drp
AviraHEUR/AGEN.1116018
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASCommon.168
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ursu.519232 (2x)
AhnLab-V3Trojan/Win32.Banki.R213572
Acronissuspicious
McAfeeArtemis!0628E3F44391
MAXmalware (ai score=99)
VBA32Trojan.Autoit.F
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_Lokmwiz.R002C0CFE21
RisingTrojan.Generic@ML.96 (RDML:TcFdWgvvuTVGFg68ZC1SFw)
YandexTrojan.GenAsa!IZxoZO1iAfE
IkarusTroajn-Ransom.Crypt888
MaxSecureTrojan.Autoit.AZA
FortinetAutoIt/Agent.BQ!tr
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml

How to remove AIT:Trojan.Nymeria.4018 (B)?

AIT:Trojan.Nymeria.4018 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment