Trojan

How to remove “Trojan.Nisloder”?

Malware Removal

The Trojan.Nisloder is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Nisloder virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system

How to determine Trojan.Nisloder?


File Info:

name: C89EC0E25B82FA7DC745.mlw
path: /opt/CAPEv2/storage/binaries/4494db9fe21c1079e5b2d394d62097be1bf6501ce0cddccef99564e2b551da3f
crc32: 9FE82891
md5: c89ec0e25b82fa7dc745f2af304f7570
sha1: 343c8152abac7a9df7f99bf4ac41663adb9faa70
sha256: 4494db9fe21c1079e5b2d394d62097be1bf6501ce0cddccef99564e2b551da3f
sha512: 1d5893b6d656deb96d8a97d7c505a0751825b610f3aa35da6905c8306c68732205cd2cf4e5041ccd0af0149ca697ec5fde3df5d6742fdc6b6b7d948d8c40646f
ssdeep: 12288:hbd3HwFrp0Czrc3/m8jG9+reazRO70oH5eOk+hlud4OABYTEnimUcjw6T91Jv6nb:hbd3Hwhp0Gc3/m8y8zohlu9AiEicQbf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17AF423813EB25979C1ABBA723B4BA792D272DD080A7B57072FE7927C1C323C34466459
sha3_384: c99ba93985b778232908edc75a18a381d297d03ddb5f463e8fef1ea7f49dc58a141cca14df93c5cd12585ae280ceb0f3
ep_bytes: 81ec8401000053555633db57895c2418
timestamp: 2014-10-07 04:40:17

Version Info:

0: [No Data]

Trojan.Nisloder also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4356
MicroWorld-eScanTrojan.GenericKD.12513907
FireEyeGeneric.mg.c89ec0e25b82fa7d
CAT-QuickHealRansom.Onion.A
ALYacTrojan.GenericKD.12513907
CylanceUnsafe
SangforTrojan.Win32.CTBLocker.A
K7AntiVirusTrojan ( 004dcfc21 )
AlibabaRansom:Win32/Cryptor.872194a0
K7GWTrojan ( 004dcfc21 )
Cybereasonmalicious.25b82f
BitDefenderThetaGen:NN.ZedlaF.34806.bC8@auLlDhd
VirITTrojan.Win32.Dropper.WP
SymantecPacked.NSISPacker!g6
ESET-NOD32Win32/Filecoder.CTBLocker.A
TrendMicro-HouseCallRansom_CRYPCTB.AF
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Cryptor.dj
BitDefenderTrojan.GenericKD.12513907
NANO-AntivirusTrojan.Win32.Encoder.eedxvl
AvastWin32:Malware-gen
TencentWin32.Trojan.Cryptor.Szvi
Ad-AwareTrojan.GenericKD.12513907
EmsisoftTrojan.GenericKD.12513907 (B)
ComodoMalware@#1jhhnjd87zosp
VIPRETrojan.GenericKD.12513907
TrendMicroRansom_CRYPCTB.AF
McAfee-GW-EditionBehavesLike.Win32.Dropper.bc
Trapminesuspicious.low.ml.score
SophosML/PE-A + Mal/Cerber-Z
IkarusTrojan.Win32.Injector
GDataTrojan.GenericKD.12513907
WebrootTrojan.Dropper.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.5174
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Generic.DBEF273
ViRobotTrojan.Win32.S.CTB-Locker.782541
MicrosoftRansom:Win32/Critroni
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.CTBLocker.R183951
McAfeeArtemis!C89EC0E25B82
TACHYONRansom/W32.Cryptor.782541
VBA32Trojan.Nisloder
MalwarebytesRansom.CTBLocker
APEXMalicious
RisingTrojan.Generic@AI.95 (RDML:E7/iIECs9Ugc8VK3UKmbmw)
YandexTrojan.GenAsa!BKRcJEcmJcE
MAXmalware (ai score=100)
FortinetW32/Injector.DAJC!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Nisloder?

Trojan.Nisloder removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment