PUA

Should I remove “NSIS:Loderka-AD [PUP]”?

Malware Removal

The NSIS:Loderka-AD [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Loderka-AD [PUP] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine NSIS:Loderka-AD [PUP]?


File Info:

name: FCF868884481855F008F.mlw
path: /opt/CAPEv2/storage/binaries/1c9fd19bdc44acd5df46c0b73e18d8c59602ff814be2cf51a2ce736eb27f0573
crc32: 757AC37F
md5: fcf868884481855f008f57cd5d4977a3
sha1: 0e8f0c6026b360dec699d77e854a0615251d713b
sha256: 1c9fd19bdc44acd5df46c0b73e18d8c59602ff814be2cf51a2ce736eb27f0573
sha512: 15de796f2b984888b35f24c991fccb6dbf966dd6d15d50fd97d9430a181c3ec07a4e7063b04e2e566993c9f8e252caca3e98f0fce0e6311b6adf32889247f4b3
ssdeep: 98304:tvngCcH+i9rItzzFidaXRpYSp7+4k1kUxrwdm:tvny+eIt5idaX3fp7RkNrqm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BE163397B3C3047AF86B013DAC4260987D6AF53924D2512E3DF5D75F0AB93C1ACBA624
sha3_384: f6145e0dd68539eb5acd2061182dad0556e0790e639b567d63b2a001ab6df88a0aad504a8e7a9d9af5237d255a8052c9
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-10-02 05:04:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: xatab
FileDescription: Setup For Euro Truck Simulator 2
FileVersion: 1.0.0
LegalCopyright: © xatab
ProductName: Euro Truck Simulator 2
ProductVersion: 1.37.1.0
Translation: 0x0000 0x04b0

NSIS:Loderka-AD [PUP] also known as:

BkavW32.AIDetectMalware
Cylanceunsafe
SangforAdware.Win32.Loderka.Vo1s
AlibabaAdWare:Win32/Loderka.6a729e47
CrowdStrikewin/grayware_confidence_100% (D)
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/Adware.Loderka.B
AvastNSIS:Loderka-AD [PUP]
DrWebAdware.Downware.19903
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Agent
MicrosoftProgram:Win32/Bitrepeyu.B
GDataWin32.Application.Agent.F38HIA
MalwarebytesGeneric.Malware/Suspicious
MaxSecureTrojan.Malware.218664370.susgen
FortinetAdware/Loderka
AVGNSIS:Loderka-AD [PUP]
DeepInstinctMALICIOUS

How to remove NSIS:Loderka-AD [PUP]?

NSIS:Loderka-AD [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment