PUA

NSIS:Adloader-H [PUP] removal tips

Malware Removal

The NSIS:Adloader-H [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Adloader-H [PUP] virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine NSIS:Adloader-H [PUP]?


File Info:

name: B7A3C6E837680E21A3DA.mlw
path: /opt/CAPEv2/storage/binaries/779ac9e3f6b76fe037191159e995333e4ce01558632190b3220b9a44ed7f70ca
crc32: 33983E22
md5: b7a3c6e837680e21a3da8f8270304070
sha1: eaf0e74f6a0aacb22fcecc64d2c6865ecad52530
sha256: 779ac9e3f6b76fe037191159e995333e4ce01558632190b3220b9a44ed7f70ca
sha512: 532fe13779dd2625aa5472a606b2744eda5fbb9776c72438bc5b17e027bcea5ffccf1c8774219f9e70c5cbe59fd7ae50bea91c8c4b327d13e8c5764c74c988c1
ssdeep: 1536:fQpQ5EP0ijnRTXJNh4Romu/TIW57v8OYLpyjT1CfqqDDK1h:fQIURTXJr45JWHKp8CyH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D73E01A32C0D8B7E66667315AB7C7BBEBF7E700066007131F546F7F6C210439A06286
sha3_384: 6615944eac56c4d415c2c9cc5a8a6c2acbf0d7ce91899d2600f05d7aabe43ea5307bab748c5fae78de5ff974072d8a93
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

NSIS:Adloader-H [PUP] also known as:

LionicAdware.Win32.AdLoad.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Application.Downloader.InstallMonster.2.084euY@b4EBb0ki
FireEyeGen:Application.Downloader.InstallMonster.2.084euY@b4EBb0ki
CAT-QuickHealTrojan.NSIS.Adload.A
SkyhighBehavesLike.Win32.Suspicious.lc
McAfeeArtemis!B7A3C6E83768
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Adload.1
K7AntiVirusTrojan ( 0052c0661 )
AlibabaAdWare:Win32/AdLoad.cbfbf639
K7GWTrojan ( 0052c0661 )
CrowdStrikewin/grayware_confidence_100% (W)
BaiduNSIS.Trojan-Downloader.Adload.j
SymantecTrojan.Gen.MBT
ESET-NOD32NSIS/TrojanDownloader.Adload.R
APEXMalicious
Kasperskynot-a-virus:AdWare.Win32.AdLoad.hmnr
BitDefenderGen:Application.Downloader.InstallMonster.2.084euY@b4EBb0ki
NANO-AntivirusTrojan.Nsis.AdLoad.eqqray
SUPERAntiSpywarePUP.AdLoad/Variant
AvastNSIS:Adloader-H [PUP]
TencentWin32.Trojan-Downloader.Adload.Pqil
SophosGeneric Reputation PUA (PUA)
F-SecureAdware.ADWARE/Adware.Gen7
DrWebTrojan.Vittalia.1482
VIPREGen:Application.Downloader.InstallMonster.2.084euY@b4EBb0ki
TrendMicroTROJ_GEN.R06BC0PJ723
Trapminemalicious.high.ml.score
EmsisoftGen:Application.Downloader.InstallMonster.2.084euY@b4EBb0ki (B)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=100)
GDataNSIS.Application.PUPDownloader.D
GoogleDetected
AviraADWARE/Adware.Gen7
VaristW32/Adload.GX.gen!Eldorado
Antiy-AVLTrojan[Downloader]/NSIS.AdLoad.r
Kingsoftmalware.kb.a.758
XcitiumApplicUnwnt@#3onkqxvian224
ArcabitApplication.Downloader.InstallMonster.2.E94539
ZoneAlarmnot-a-virus:AdWare.Win32.AdLoad.hmnr
MicrosoftSoftwareBundler:Win32/Penzievs
CynetMalicious (score: 100)
ALYacGen:Application.Downloader.InstallMonster.2.084euY@b4EBb0ki
TACHYONTrojan-Clicker/W32.Adload.76887
VBA32Adware.AdLoad
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R06BC0PJ723
RisingDownloader.AdLoad/NSIS!1.A0F0 (CLASSIC)
IkarusTrojan.NSIS.Adload
FortinetW32/Adload.R!tr.dldr
AVGNSIS:Adloader-H [PUP]
Cybereasonmalicious.f6a0aa
DeepInstinctMALICIOUS

How to remove NSIS:Adloader-H [PUP]?

NSIS:Adloader-H [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment