Trojan

Should I remove “AIT:Trojan.Nymeria.988”?

Malware Removal

The AIT:Trojan.Nymeria.988 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AIT:Trojan.Nymeria.988 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine AIT:Trojan.Nymeria.988?


File Info:

name: 81C9E834B72D12577F07.mlw
path: /opt/CAPEv2/storage/binaries/f6942d56d765ee7e9dcbf0773a02a78fd35320cc6bf071f99df0be7ca66c7fb1
crc32: 81E91F6E
md5: 81c9e834b72d12577f07f277cd8844f3
sha1: 3f1209b2541777bb53cbcda42c7b4cbbd76905e4
sha256: f6942d56d765ee7e9dcbf0773a02a78fd35320cc6bf071f99df0be7ca66c7fb1
sha512: b9db8053af30281828e91f3623db2a88ccd2dc9ebc2d618f9e6c7fafc9e290519a2b6a23be2c12f8a74d9e5b9917035447d8f8e36cffb0ac68ea42d01f64ffc0
ssdeep: 12288:otb20Qc3lT7af41ePBRYuQLKpqeUhbTv5OFgNuPPpHSgaFxKm1LZrpjXV+2Shglg:otb20pkaCqT5TBWgNQ7a3J1B2Slu6A
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D459C127F9D826DC2725173FB156F01AE6B7C2506A1B47B2FD4392CAB3C121D31AA63
sha3_384: 545c8bafc58b5edb0598227dad55ef824e481f7c17f8bc1a2add12003a49f6eb3ab8f093e77ccc41ff3521beb1dea36b
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2018-07-19 05:24:45

Version Info:

Translation: 0x0809 0x04b0

AIT:Trojan.Nymeria.988 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.11776
MicroWorld-eScanAIT:Trojan.Nymeria.988
FireEyeGeneric.mg.81c9e834b72d1257
CAT-QuickHealTrojan.AutoIt.Downloader.ZZ
ALYacAIT:Trojan.Nymeria.988
CylanceUnsafe
SangforTrojan.Win32.Malware.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/AutoitCrypt.180
K7GWTrojan ( 005376711 )
K7AntiVirusTrojan ( 005376711 )
ArcabitAIT:Trojan.Nymeria.988
BitDefenderThetaAI:Packer.A1FB285916
VirITTrojan.Win32.MulDrp.AJEJ
ESET-NOD32a variant of Win32/Injector.Autoit.DJG
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Autoit-6961385-0
KasperskyTrojan.Win32.Autoit.fld
BitDefenderAIT:Trojan.Nymeria.988
NANO-AntivirusTrojan.Win32.Autoit.ffmsoh
AvastFileRepMalware [Trj]
TencentWin32.Trojan.Autoit.Eanh
Ad-AwareAIT:Trojan.Nymeria.988
EmsisoftAIT:Trojan.Nymeria.988 (B)
ComodoMalware@#3ujjr7kq3k3wi
TrendMicroTROJ_FRS.VSN14G18
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
Trapminemalicious.high.ml.score
SophosMal/Generic-S
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1245425
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataAIT:Trojan.Nymeria.988 (2x)
CynetMalicious (score: 99)
McAfeeArtemis!81C9E834B72D
VBA32Trojan.Autoit
TrendMicro-HouseCallTROJ_FRS.VSN14G18
RisingTrojan.Injector/Autoit!1.BB8F (CLASSIC)
IkarusTrojan.Inject
FortinetAutoIt/Injector.ELS!tr
AVGFileRepMalware [Trj]
Cybereasonmalicious.4b72d1
PandaTrj/CI.A

How to remove AIT:Trojan.Nymeria.988?

AIT:Trojan.Nymeria.988 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment