Trojan

AIT:Trojan.Nymeria.4914 malicious file

Malware Removal

The AIT:Trojan.Nymeria.4914 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.4914 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
pomf.lain.la

How to determine AIT:Trojan.Nymeria.4914?


File Info:

crc32: A1EFCC63
md5: d3cb74f54e234ecdabc5793ae5b867b7
name: D3CB74F54E234ECDABC5793AE5B867B7.mlw
sha1: d1bc7c19b359d0a46baf7b1661af4f9b849e6d30
sha256: 9ce715356f2ec1c2cee6f0f1f7e1f8533b3a6be2485c85fc802d3ff95fb447e1
sha512: ac3031ec898aa54af6048f7ec198d50daae71b4e3829e77ef6e8a05796fd467d3a3cf26357f86ed573b09e5aadfe60c4425382e3c2a0fb3e2b90ff1adf74769d
ssdeep: 12288:IXe9PPlowWX0t6mOQwg1Qd15CcYk0We1Krx:FhloDX0XOf4Erx
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.4914 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CylanceUnsafe
BitDefenderAIT:Trojan.Nymeria.4914
Cybereasonmalicious.9b359d
CyrenW32/AutoIt.UT.gen!Eldorado
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-PSW.MSIL.Agensla.vdf
MicroWorld-eScanAIT:Trojan.Nymeria.4914
Ad-AwareAIT:Trojan.Nymeria.4914
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.d3cb74f54e234ecd
EmsisoftAIT:Trojan.Nymeria.4914 (B)
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Script/Phonzy.C!ml
AhnLab-V3Trojan/Win.Generic.R438995
MAXmalware (ai score=85)
MalwarebytesMalware.AI.2816667347
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Injector.BFC6!tr

How to remove AIT:Trojan.Nymeria.4914?

AIT:Trojan.Nymeria.4914 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment