Trojan

About “AIT:Trojan.Nymeria.81” infection

Malware Removal

The AIT:Trojan.Nymeria.81 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.81 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Anomalous binary characteristics

How to determine AIT:Trojan.Nymeria.81?


File Info:

crc32: 0AACAF4F
md5: b131cc3b5322807102f1c942d6d9f3f6
name: B131CC3B5322807102F1C942D6D9F3F6.mlw
sha1: fba13a86d6fdaf98a9276374d9f0f1ed2c91e61a
sha256: c3e6c301b8372bb630580858bfbe470ab9cdacd5a22c95a18285b328c8162257
sha512: 0ca0fdc10ae51e6f9e85d1cb9bacaa9a7116b62676c3e85a08437aba17d7e3fcc8dd0c4044e56896d48593d51e012c06c69a3e0f2e9e54349cc0d1018d3bfc2c
ssdeep: 24576:LXdSGJ2Eq2bqTWioAM/jAEneauJ09q9MmCS:h55bqxoAMZeauJgaPCS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.81 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanAIT:Trojan.Nymeria.81
FireEyeGeneric.mg.b131cc3b53228071
CAT-QuickHealTrojanPWS.AutoIt.Zbot.S
McAfeeArtemis!B131CC3B5322
CylanceUnsafe
SangforMalware
BitDefenderAIT:Trojan.Nymeria.81
Cybereasonmalicious.b53228
BitDefenderThetaAI:Packer.4A7CAE7C15
CyrenW32/AutoIt.EZ.gen!Eldorado
SymantecBackdoor.Ratenjay
BaiduWin32.Trojan-Dropper.Autoit.c
APEXMalicious
ClamAVWin.Trojan.Autoit-9790251-0
KasperskyTrojan-Dropper.Win32.Autoit.bpz
NANO-AntivirusTrojan.Script.AutoIt.dcckyk
Ad-AwareAIT:Trojan.Nymeria.81
EmsisoftAIT:Trojan.Nymeria.81 (B)
F-SecureHeuristic.HEUR/AGEN.1134155
DrWebTrojan.DownLoader35.27056
InvinceaTroj/Autoit-BIF
McAfee-GW-EditionBehavesLike.Win32.DownloaderAutoIt.ch
SophosTroj/Autoit-BIF
IkarusTrojan-Dropper.Win32.Autoit
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1134155
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitAIT:Trojan.Nymeria.81
AhnLab-V3Dropper/RL.Autoit.R242657
ZoneAlarmTrojan-Dropper.Win32.Autoit.bpz
GDataAIT:Trojan.Nymeria.81 (2x)
CynetMalicious (score: 100)
ESET-NOD32multiple detections
MAXmalware (ai score=81)
MalwarebytesBackdoor.Bladabindi.AutoIt
eGambitUnsafe.AI_Score_85%
FortinetW32/Autoit.AWL!tr
AVGAutoIt:Runner-AN [Trj]
AvastAutoIt:Runner-AN [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove AIT:Trojan.Nymeria.81?

AIT:Trojan.Nymeria.81 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment