Trojan

Should I remove “Trojan.Nymeria.AutoIt”?

Malware Removal

The Trojan.Nymeria.AutoIt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Nymeria.AutoIt virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
nickdns29.duckdns.org

How to determine Trojan.Nymeria.AutoIt?


File Info:

crc32: 83AD20E6
md5: 5e649d4db015bcbec0971bd30372e510
name: 5E649D4DB015BCBEC0971BD30372E510.mlw
sha1: e65c0802cdea66b38fa64abc89350db60227bef6
sha256: 028c3554cc3a21019a76ab84c1a8210589be75d33de17ebe06db525c5dfe9527
sha512: d79fc9619cc15b29ba2fef1087e443ebd9c117d985efdbee4f1bf3e2f3e7b956e852e21a3186a34e29a7e06de9afe16688fbda3204ed93e8f3b66ee9dd3ec10f
ssdeep: 24576:Dtb20pkaCqT5TBWgNQ7a3DFlBQL79ecVV6Aq:AVg5tQ7azFlO9D5q
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Corythus
Assembly Version: 1.4.3.6
InternalName: damaskine.exe
FileVersion: 8.8.7.1
CompanyName: eucarpous
LegalTrademarks: Valrico
Comments: stalest
ProductName: pilgrimer
ProductVersion: 8.8.7.1
FileDescription: Orosius
OriginalFilename: damaskine.exe

Trojan.Nymeria.AutoIt also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 700000111 )
LionicTrojan.MSIL.NanoBot.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Nanocore.23
CynetMalicious (score: 99)
ALYacAIT:Trojan.Nymeria.1418
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:MSIL/NanoBot.473e1864
K7GWTrojan ( 700000111 )
Cybereasonmalicious.db015b
CyrenW32/AutoIt.QA2.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.Autoit.DMI
APEXMalicious
AvastScript:SNH-gen [Trj]
KasperskyBackdoor.MSIL.NanoBot.ahpj
BitDefenderAIT:Trojan.Nymeria.1418
NANO-AntivirusTrojan.Win32.Nanocore.fjxmys
MicroWorld-eScanAIT:Trojan.Nymeria.1418
TencentMsil.Backdoor.Nanobot.Syie
Ad-AwareAIT:Trojan.Nymeria.1418
SophosMal/Generic-S
ComodoMalware@#3s7i0gjxbptxs
BitDefenderThetaAI:Packer.2778C02417
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.5e649d4db015bcbe
EmsisoftAIT:Trojan.Nymeria.1418 (B)
AviraDR/AutoIt.Gen8
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataAIT:Trojan.Nymeria.1418 (2x)
AhnLab-V3Trojan/Win32.NanoBot.R243074
McAfeeArtemis!5E649D4DB015
MAXmalware (ai score=99)
VBA32Backdoor.MSIL.NanoBot
MalwarebytesTrojan.Nymeria.AutoIt
PandaTrj/CI.A
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Injector.DLX!tr
AVGScript:SNH-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan.Nymeria.AutoIt?

Trojan.Nymeria.AutoIt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment