Trojan

AIT:Trojan.Nymeria.5509 removal

Malware Removal

The AIT:Trojan.Nymeria.5509 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.5509 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine AIT:Trojan.Nymeria.5509?


File Info:

name: BB72586C2BA3001E50AB.mlw
path: /opt/CAPEv2/storage/binaries/c640f6e4e74838d7ef6e62f814c0d64ec0f311495c936897d5525ef4f8a665eb
crc32: 228B16AA
md5: bb72586c2ba3001e50abf7629567e521
sha1: a7156606380d5f1a16bf88d85aa06cc3a41ed138
sha256: c640f6e4e74838d7ef6e62f814c0d64ec0f311495c936897d5525ef4f8a665eb
sha512: ea8e34384e34a9a7028d0275ef99a06538bda21b021a60152f6267140ce63a1a460006d51e314efecfd979d968a46358a410b024dbb34bc3f2d65f0a2e3b7a81
ssdeep: 12288:Atb20Qc3lT7af41ePBRYuQLKpqeUhbTv5OFgNuPPpHSgaFCH6A:Atb20pkaCqT5TBWgNQ7aFCH6A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD157D22639D8394C7F266737A157711BFAF7C2A06A0B45B5FD83CBCE830061574B6A2
sha3_384: b9a3d7da4aa828422a395de47ebeae657d60f77c4231525d1929628434ad64e2fe3d4e2e38dc895164264bc1253941a0
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2015-03-10 01:41:12

Version Info:

FileVersion: 3.3.12.0
Comments: http://www.autoitscript.com/autoit3/
FileDescription: Aut2Exe
ProductVersion: 3.3.12.0
LegalCopyright: ©1999-2014 Jonathan Bennett & AutoIt Team
Translation: 0x0804 0x04b0

AIT:Trojan.Nymeria.5509 also known as:

BkavW32.Common.78FBCEB1
LionicTrojan.Win32.Nymeria.4!c
MicroWorld-eScanAIT:Trojan.Nymeria.5509
FireEyeAIT:Trojan.Nymeria.5509
SkyhighBehavesLike.Win32.Ransomware.dh
ALYacAIT:Trojan.Nymeria.5509
Cylanceunsafe
SangforTrojan.Win32.Agent.Vbjz
AlibabaTrojan:AutoIt/MalOb.5da106ff
ArcabitAIT:Trojan.Nymeria.D1585 [many]
CynetMalicious (score: 100)
APEXMalicious
BitDefenderAIT:Trojan.Nymeria.5509
NANO-AntivirusTrojan.Script.AutoIt.dcckyk
AvastAutoIt:MalOb-HY [Trj]
EmsisoftAIT:Trojan.Nymeria.5509 (B)
VIPREAIT:Trojan.Nymeria.5509
TrendMicroTROJ_GEN.R002C0PAU24
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataAIT:Trojan.Nymeria.5509 (2x)
McAfeeRDN/Generic.dx
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0PAU24
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.230150084.susgen
AVGAutoIt:MalOb-HY [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove AIT:Trojan.Nymeria.5509?

AIT:Trojan.Nymeria.5509 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment