Trojan

What is “AIT:Trojan.Nymeria.4899”?

Malware Removal

The AIT:Trojan.Nymeria.4899 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.4899 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine AIT:Trojan.Nymeria.4899?


File Info:

name: 0BB814D4A1E881FAE438.mlw
path: /opt/CAPEv2/storage/binaries/818e6af607935be6395a9cbe700f5fea23a523ba8329523e2f0d637a8e34ea2f
crc32: EA2F2169
md5: 0bb814d4a1e881fae438644aa0a8decc
sha1: 63073e41d5416a2362f5bf2bede65a73aed2c6d4
sha256: 818e6af607935be6395a9cbe700f5fea23a523ba8329523e2f0d637a8e34ea2f
sha512: b0a675901e423b209936cbbae28e12331ee8015f07d19e82df2131aa008d2aec78032da197223bde5cab50512ae5fc473ea7910e02ce8d38ec490ede9756be77
ssdeep: 12288:+i+ETezCHQkZPhprhmH6ukWAljnQlnl2OdpbxZDmRmFaoIhsJMY:+iQsFhBhmAWAdnQxlfj6YaDKqY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A5F4AF22F5D78072C5A22271CDBEF776963DB93A0323C6EB27C81D355EA0541762A372
sha3_384: 5513d21a18cba0c1fda001f5594a216aa4a20f0f65a9bbaffefa8300ba62bdec4b064f53c6b035af958a99b6dd3c1488
ep_bytes: e8dec20000e989feffffcccccccccccc
timestamp: 2012-02-04 22:43:24

Version Info:

FileVersion: 0.0.0.205
Comments: 本地KMS激活,无需联网
FileDescription: HEU KMS Activator
LegalCopyright: Copyright(C) 2012-2013 By Zbezj
CompanyName: HEU CNST
Translation: 0x0804 0x04b0

AIT:Trojan.Nymeria.4899 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.4899
FireEyeGeneric.mg.0bb814d4a1e881fa
ALYacAIT:Trojan.Nymeria.4899
CylanceUnsafe
K7AntiVirusTrojan ( 700000111 )
K7GWTrojan ( 700000111 )
Cybereasonmalicious.1d5416
CyrenW32/Trojan.IJBN-1595
SymantecTrojan.ADH
ESET-NOD32a variant of Win32/HackKMS.Z potentially unsafe
APEXMalicious
ClamAVWin.Malware.Autoit-6753917-0
BitDefenderAIT:Trojan.Nymeria.4899
AvastWin32:PUP-gen [PUP]
Ad-AwareAIT:Trojan.Nymeria.4899
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Hider.REXR@5364l6
EmsisoftAIT:Trojan.Nymeria.4899 (B)
GDataWin32.Riskware.HackKMS.L
AviraTR/Dropper.Gen
ViRobotTrojan.Win32.A.Agent.690283
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Unwanted/Win32.KMSActivator.R202307
MAXmalware (ai score=82)
VBA32IMWorm.Sohanad
MalwarebytesRiskWare.KMS
YandexTrojan.GenAsa!i9rai7w7/WE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:PUP-gen [PUP]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove AIT:Trojan.Nymeria.4899?

AIT:Trojan.Nymeria.4899 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment