Trojan

AIT:Trojan.Nymeria.4640 removal tips

Malware Removal

The AIT:Trojan.Nymeria.4640 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.4640 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine AIT:Trojan.Nymeria.4640?


File Info:

name: 020531FF2988A33E2142.mlw
path: /opt/CAPEv2/storage/binaries/30d8e6141c6d801b1b0a47059cd7eac163312f9c91231d406c927b4cf635408a
crc32: 8CC29EBA
md5: 020531ff2988a33e2142ab03160a3119
sha1: 3f26e75cc236ebba480ea99d4c5a3836cea743cb
sha256: 30d8e6141c6d801b1b0a47059cd7eac163312f9c91231d406c927b4cf635408a
sha512: 02981d12e9902d5bf1284db8ee76c08affa3d09b16f3375c3b527a714b652f8bf38d8fb62ffcbe53181b6c6e88cbcfdbcbf16d30762389a28ad351c054806247
ssdeep: 49152:6kwkn9IMHeaessKeva6RiGfaES8VmsaPCS:pdnVTevfaEFVmPC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15775E01373DE83A5C3729173BA55BB01AEBB7C2506B1F59B2FD8093DE920121921E673
sha3_384: 90904c7a1d2b546fd75b41f54905b9fa3f9e572f32e35d2584fd223ac421ac0a71b5f8b58bee7a94afb6c897169449b3
ep_bytes: e897cf0000e97ffeffffcccccccccccc
timestamp: 2023-09-19 20:45:43

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.4640 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.4640
MalwarebytesMachineLearning/Anomalous.100%
VIPREAIT:Trojan.Nymeria.4640
BitDefenderAIT:Trojan.Nymeria.4640
Cybereasonmalicious.cc236e
ESET-NOD32a variant of Win32/Autoit.EJ
APEXMalicious
ClamAVTxt.Malware.LodaRAT-9769386-0
KasperskyHEUR:Backdoor.Script.LodaRat.a
AvastAutoIt:KeyLogger-R [Trj]
EmsisoftAIT:Trojan.Nymeria.4640 (B)
F-SecureHeuristic.HEUR/AGEN.1353217
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.020531ff2988a33e
SophosGeneric ML PUA (PUA)
IkarusTrojan.Autoit
GDataAIT:Trojan.Nymeria.4640 (2x)
GoogleDetected
AviraHEUR/AGEN.1353217
MAXmalware (ai score=89)
ArcabitAIT:Trojan.Nymeria.D1220 [many]
ZoneAlarmHEUR:Backdoor.Script.LodaRat.a
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
ALYacAIT:Trojan.Nymeria.4640
VBA32Trojan.Autoit.F
Cylanceunsafe
RisingBackdoor.888Rat/Autoit!1.C8E3 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/KeyLogger.R!tr
BitDefenderThetaAI:Packer.1D0DF3E616
AVGAutoIt:KeyLogger-R [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove AIT:Trojan.Nymeria.4640?

AIT:Trojan.Nymeria.4640 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment