Trojan

Trojan.Loader.Nyan removal

Malware Removal

The Trojan.Loader.Nyan is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Loader.Nyan virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan.Loader.Nyan?


File Info:

name: C5FE1E9F61BA007E0AB9.mlw
path: /opt/CAPEv2/storage/binaries/88ecac2702cc03f1f4a2fddbd59cbb9da227ab07756cf095158a8635b05f3645
crc32: 2260C800
md5: c5fe1e9f61ba007e0ab9b5ffc787354d
sha1: fc87b0e4f29e0466365d73a3ec6790248a52415f
sha256: 88ecac2702cc03f1f4a2fddbd59cbb9da227ab07756cf095158a8635b05f3645
sha512: 5c94f94e3c260ef73ea94809fcb6fb74b49d0e244bfc5467e37220300d01a52265584fd8eeab7eda833988390195e2e2c304197ad8a61d223a5b6d8b428e4dc6
ssdeep: 384:mJJf0bUe5XB4e0X7Od/w0Q0mS03AWTxtTUFQqzF/ObbZhYtsF96/0kKlO:mJCT9BuCi55dpbZ8k9aNKlO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10703F60677E84225D6BD1BB89CB303214B72F6838432EB5F5CDC448E5FA7B904651AF9
sha3_384: 93a5d9cfd6a8a84d9226daadab88eef250fdb55304174060346d68395fc6d5117e2529add8b4362279e61a66098e3487
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-07 16:16:41

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: 1.exe
LegalCopyright:
OriginalFilename: 1.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Trojan.Loader.Nyan also known as:

LionicTrojan.MSIL.KeyLogger.l!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop11.26182
MicroWorld-eScanIL:Trojan.MSILZilla.5327
FireEyeGeneric.mg.c5fe1e9f61ba007e
CAT-QuickHealTrojan.MsilFC.S20327749
ALYacIL:Trojan.MSILZilla.5327
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaRansom:MSIL/FileCoder.c1890f7d
K7GWTrojan ( 700000121 )
Cybereasonmalicious.f61ba0
BitDefenderThetaAI:Packer.B1D110C41F
CyrenW32/MSIL_Agent.BTN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.TET
TrendMicro-HouseCallRansom_FileCoder.R002C0DL721
Paloaltogeneric.ml
ClamAVWin.Packed.njRAT-7445143-0
KasperskyHEUR:Trojan-Spy.MSIL.KeyLogger.gen
BitDefenderIL:Trojan.MSILZilla.5327
AvastMSIL:Bladabindi-JK [Trj]
TencentMsil.Trojan-spy.Keylogger.Tayw
Ad-AwareIL:Trojan.MSILZilla.5327
EmsisoftIL:Trojan.MSILZilla.5327 (B)
BaiduMSIL.Backdoor.Bladabindi.a
TrendMicroRansom_FileCoder.R002C0DL721
McAfee-GW-EditionGenericRXIQ-YQ!C5FE1E9F61BA
SophosMal/Generic-S
IkarusTrojan.MSIL.Bladabindi
GDataIL:Trojan.MSILZilla.5327
JiangminTrojanSpy.MSIL.cazq
AviraTR/Dropper.Gen7
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.34E6238
GridinsoftRansom.Win32.Bladabindi.sa
ViRobotTrojan.Win32.Z.Bladabindi.39936.PJ
MicrosoftRansom:MSIL/FileCoder!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MSILKrypt.R326643
McAfeeGenericRXIQ-YQ!C5FE1E9F61BA
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Loader.Nyan
APEXMalicious
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinMiner.TET!tr
AVGMSIL:Bladabindi-JK [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.Loader.Nyan?

Trojan.Loader.Nyan removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment