Trojan

Trojan.Win32.Nisloder.gdg (file analysis)

Malware Removal

The Trojan.Win32.Nisloder.gdg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Nisloder.gdg virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Trojan.Win32.Nisloder.gdg?


File Info:

crc32: DAB1EDA1
md5: 79bd8aa75000cf30cb743f67b33add81
name: 79BD8AA75000CF30CB743F67B33ADD81.mlw
sha1: b92f976c03373573f0802f9004b6866c1ff4233a
sha256: 05c409822a687ba2e33538c022ccfcdc93d517ef23232c6ab6e28622ddb13378
sha512: c666eeb55e8eaf21cbfe44d20f81dee361732656415839137eeda3ac290979eb72f4e1a1f8548cfc34cb03a728dc0a0566057f0dc76b83f461c7fa96aec05bdb
ssdeep: 6144:mMMYNXqBBNftBhB7KBfM5CUEodlOLXxI4zydYNYwV3BzDyzubl8N8+1uqN:qnNMqhEBLG4uQ3hDquqKqT
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan.Win32.Nisloder.gdg also known as:

K7AntiVirusTrojan ( 004e24c81 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.761
CynetMalicious (score: 100)
ALYacTrojan.Ransom.cryptolocker
CylanceUnsafe
SangforTrojan.Win32.Injector.8
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Nisloder.6294bac7
K7GWTrojan ( 004e24c81 )
Cybereasonmalicious.75000c
SymantecRansom.CryptXXX
ESET-NOD32Win32/Filecoder.TorrentLocker.A
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Nisloder.gdg
BitDefenderTrojan.GenericKD.4989551
NANO-AntivirusTrojan.Win32.GenericKD.eokbnw
MicroWorld-eScanTrojan.GenericKD.4989551
TencentWin32.Backdoor.Androm.Akft
Ad-AwareTrojan.GenericKD.4989551
SophosTroj/TorLock-W
ComodoMalware@#16aiumvrvg89h
BitDefenderThetaGen:NN.ZedlaF.34050.dq4@aawr4Vb
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPLOCK.XL
McAfee-GW-EditionRansom-O.a
FireEyeGeneric.mg.79bd8aa75000cf30
EmsisoftTrojan.GenericKD.4989551 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1116998
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftRansom:Win32/Teerac
SUPERAntiSpywareRansom.CryptoLocker/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.GenericKD.4989551
AhnLab-V3Trojan/Win32.RL_Zerber.R283225
McAfeeArtemis!79BD8AA75000
MAXmalware (ai score=86)
VBA32Backdoor.Androm
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CRYPLOCK.XL
RisingTrojan.Generic@ML.96 (RDML:4jAEkHtt8YtQBlu4v+Micg)
YandexTrojan.Injector!wpumw8auOMQ
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DOLU!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HyoDEpsA

How to remove Trojan.Win32.Nisloder.gdg?

Trojan.Win32.Nisloder.gdg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment