Trojan

AIT:Trojan.Nymeria.4177 removal

Malware Removal

The AIT:Trojan.Nymeria.4177 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.4177 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine AIT:Trojan.Nymeria.4177?


File Info:

name: D58A289B4B385B4EC1E5.mlw
path: /opt/CAPEv2/storage/binaries/16acda749390005716c5561afd9d2991be16714a9fee8d457f9ef586b5e771b3
crc32: DF606704
md5: d58a289b4b385b4ec1e51ba62f3ca945
sha1: 4c3878e7c188636006991875aae47489162f0346
sha256: 16acda749390005716c5561afd9d2991be16714a9fee8d457f9ef586b5e771b3
sha512: 3ca25eaba458ace7665e7a0200cd000e479c7ea467875ed55c59603190774a553178659bd504a5e0368bef47c39175ed18963b891db8d39ec36b73ddd4c4bbf2
ssdeep: 49152:DVg5tQ7aB775OBB69fNmHEbCdf/vk6763rqrx8KtDU6f8Di:Zg56vBBqlmkbCdf/vhyqrxzyDi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0C5022373DE8364C3B15273BA557742AE7F782506B5F96B2FD8083DA820122525EB73
sha3_384: 6b906266b4657c3669a0009ed1b644392fd76d60eebe65cffe83c7fa614535b6d52dfb3d437f9606a8e2cc6d019cf24b
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2014-10-22 01:51:39

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.4177 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Autoit.7!c
tehtrisGeneric.Malware
MicroWorld-eScanAIT:Trojan.Nymeria.4177
FireEyeGeneric.mg.d58a289b4b385b4e
McAfeeArtemis!D58A289B4B38
MalwarebytesGeneric.Malware/Suspicious
VIPREAIT:Trojan.Nymeria.4177
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004d064a1 )
AlibabaTrojanBanker:Win32/Injector.28cc1857
K7GWTrojan ( 004d064a1 )
Cybereasonmalicious.7c1886
BitDefenderThetaAI:Packer.D41613D916
VirITTrojan.Win32.MultiDropper_c.AB
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
KasperskyTrojan-Banker.Win32.Autoit.dq
BitDefenderAIT:Trojan.Nymeria.4177
NANO-AntivirusTrojan.Script.Agent.debxaj
AvastAutoIt:Injector-HL [Trj]
TencentWin32.Trojan-Banker.Autoit.Mjgl
SophosMal/Generic-R
F-SecureDropper.DR/AutoIt.Gen
DrWebTrojan.DownLoader22.13393
TrendMicroTROJ_BANLOAD.EJRH
McAfee-GW-EditionBehavesLike.Win32.RealProtect.vc
Trapminemalicious.moderate.ml.score
EmsisoftAIT:Trojan.Nymeria.4177 (B)
JiangminTrojan/Banker.AutoIt.ck
WebrootW32.Malware.Gen
GoogleDetected
AviraDR/AutoIt.Gen
Antiy-AVLTrojan[Banker]/Win32.Autoit
XcitiumMalware@#2i2l5qt88su1y
ArcabitAIT:Trojan.Nymeria.D1051 [many]
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataAIT:Trojan.Nymeria.4177 (2x)
CynetMalicious (score: 100)
VBA32TrojanBanker.Autoit
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_BANLOAD.EJRH
SentinelOneStatic AI – Suspicious PE
FortinetW32/Autoit.BBF!tr
AVGAutoIt:Injector-HL [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove AIT:Trojan.Nymeria.4177?

AIT:Trojan.Nymeria.4177 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment