Trojan

AIT:Trojan.Nymeria.638 removal

Malware Removal

The AIT:Trojan.Nymeria.638 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.638 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Harvests cookies for information gathering

How to determine AIT:Trojan.Nymeria.638?


File Info:

name: 19EB76FA4042B4CC6855.mlw
path: /opt/CAPEv2/storage/binaries/f7e6dd5fdb42f46dfee8f9b2192bc48d4c86f56df11aa3901380d2189e9cb841
crc32: CBFB11D6
md5: 19eb76fa4042b4cc68557cca7e73c0c1
sha1: db83bf465d89b9da9ac933eb93764d8e62c0cd1b
sha256: f7e6dd5fdb42f46dfee8f9b2192bc48d4c86f56df11aa3901380d2189e9cb841
sha512: b7aa05b957a9d88b6c02253d72d866a66f222653eea5f260c11115022b78c8bb061f2fcfe38aea35a9a13afb662db920315059fd4a2b1362b233aa7e3e7f38af
ssdeep: 196608:pCK4Gavs615+QOF4QsE9tWwrNz316BcUy2YsXx6FcWEMnFmShzg4LY:o/GoT+Qi4QRZ5b16D1IcWEMnF1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T186A62303B3D2D062FFA682B34B29F24696BD79244163952F13982EBDBC704B1577D263
sha3_384: bd23a54717cf1d7f183d433e63c6bf5e68f45f906513fb3ed5e524749a48f62a3ae9700ddfd208faa0a76d639716f39a
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2018-05-07 10:01:08

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.638 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.638
FireEyeGeneric.mg.19eb76fa4042b4cc
ALYacTrojan.GenericKD.44950045
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005642691 )
AlibabaTrojanPSW:Win32/Skeeyah.e93e60f9
K7GWTrojan ( 005642691 )
Cybereasonmalicious.a4042b
CyrenW32/Gobot.E.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyUDS:Trojan-PSW.Win32.Agent.a
BitDefenderAIT:Trojan.Nymeria.638
NANO-AntivirusTrojan.Win32.Stealer.faxflg
AvastWin32:Malware-gen
EmsisoftAIT:Trojan.Nymeria.638 (B)
ComodoMalware@#2qg8mwdmoojw9
DrWebTrojan.PWS.Stealer.23739
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
SophosMal/Generic-S + Troj/Stealer-UE
IkarusTrojan.SuspectCRC
AviraHEUR/AGEN.1100084
Antiy-AVLGrayWare/Autoit.Execute.a
GridinsoftRansom.Win32.Occamy.sa
MicrosoftTrojan:Win32/Occamy.CF7
ViRobotTrojan.Win32.Z.Razy.9496064.E
ZoneAlarmHEUR:Trojan-PSW.Win32.Pycoon.gen
GDataTrojan.GenericKD.44950045 (2x)
AhnLab-V3Malware/Win32.Generic.C2550811
McAfeePacked-FGH!19EB76FA4042
MAXmalware (ai score=99)
VBA32TrojanPSW.Pycoon
MalwarebytesGeneric.Malware/Suspicious
RisingStealer.Agent!8.C2 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/AutoIt.CB!tr
BitDefenderThetaAI:Packer.4953B6AF16
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (D)

How to remove AIT:Trojan.Nymeria.638?

AIT:Trojan.Nymeria.638 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment