Trojan

AIT:Trojan.Nymeria.4918 (B) removal

Malware Removal

The AIT:Trojan.Nymeria.4918 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.4918 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the WarzoneRAT malware family
  • Accesses or creates Warzone RAT directories and/or files
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine AIT:Trojan.Nymeria.4918 (B)?


File Info:

name: C04A8B4306836EB09986.mlw
path: /opt/CAPEv2/storage/binaries/bad5ad2ccac593f52c4be3d667dab25d8dace9b297dad9e6289cc4ccedc405c9
crc32: 1A74C8DA
md5: c04a8b4306836eb09986915a25482533
sha1: 485d9a9d7ef695355aad1057a33de55a436db895
sha256: bad5ad2ccac593f52c4be3d667dab25d8dace9b297dad9e6289cc4ccedc405c9
sha512: e15db3eb54fb6c81e640e71ecf5809d7430d4b81e9cfc0830d25c7f45a38c588f706493407440e81c8e3cfcabe97329e1410372187a896599c32212adcca7095
ssdeep: 24576:v4lavt0LkLL9IMixoEFNYUBth7E5xT/m:qkwkn9IMSNYUntGh/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T169359E02639DC290CA725273F925ABF16E7B7C25C570F09B2F853D3DB9721A1422E663
sha3_384: af1d627c2717e3f8f0cfb99da13862650cca51258ab27455849fc96039be888e87ac0da5684c3f18ef218fea523e752a
ep_bytes: e897cf0000e97ffeffffcccccccccccc
timestamp: 2021-09-01 07:35:53

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.4918 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win64.Zenpak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.4918
SkyhighBehavesLike.Win32.TrojanAitInject.th
McAfeeArtemis!C04A8B430683
MalwarebytesMachineLearning/Anomalous.94%
SangforVirus.Win32.Save.a
AlibabaTrojanDropper:Win32/Zenpak.a9f7f520
Cybereasonmalicious.d7ef69
ArcabitAIT:Trojan.Nymeria.D1336 [many]
SymantecTrojan.Gen.MBT
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Autoit.VW
CynetMalicious (score: 100)
APEXMalicious
KasperskyTrojan.Win64.Zenpak.yd
BitDefenderAIT:Trojan.Nymeria.4918
AvastAutoIt:Obfuscated-F [Cryp]
TencentWin64.Trojan.Zenpak.Nsmw
EmsisoftAIT:Trojan.Nymeria.4918 (B)
F-SecureHeuristic.HEUR/AGEN.1319159
VIPREAIT:Trojan.Nymeria.4918
SophosMal/Generic-S
IkarusTrojan.Inject
VaristW32/AutoIt.VB.gen!Eldorado
AviraHEUR/AGEN.1319159
Antiy-AVLTrojan/Win32.Autoit
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmTrojan.Win64.Zenpak.yd
GDataAIT:Trojan.Nymeria.4918 (2x)
GoogleDetected
AhnLab-V3Trojan/Win.Nymeria.C4623064
MAXmalware (ai score=87)
VBA32Trojan.Win64.Zenpak
Cylanceunsafe
PandaTrj/CI.A
RisingDropper.Agent/Autoit!1.D9B1 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.215121136.susgen
AVGAutoIt:Obfuscated-F [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove AIT:Trojan.Nymeria.4918 (B)?

AIT:Trojan.Nymeria.4918 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment