PUA

NSIS:Loderka-AS [PUP] removal tips

Malware Removal

The NSIS:Loderka-AS [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Loderka-AS [PUP] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine NSIS:Loderka-AS [PUP]?


File Info:

name: F16153CE61502DA898C6.mlw
path: /opt/CAPEv2/storage/binaries/fcd0995d3e25b2870f989175c9172323f93663e97944d9c1cbfa60848d10f2bb
crc32: 5969D04E
md5: f16153ce61502da898c699c4f79a4ea6
sha1: a6310cefe30c27d33d9196125b83b89f2ca1f53f
sha256: fcd0995d3e25b2870f989175c9172323f93663e97944d9c1cbfa60848d10f2bb
sha512: 032d6d60339b1b1e3dff7d6c594308753d3eac7163bc159fbc7f99f6f6ce8767e1bbc2410cb5cf0d23f1cfed175e840ea092c7eb80dcc0ef39577bb30f1b1b67
ssdeep: 49152:UiD4ymBzndS3GOThEdtkplj4NhW/xvHo9l+fbP4rG5u0/xE:g41ThEcd4N8Jv2YVFO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CAB5CDA1AE42953DCA171F34843690141C376CDB69F7D87D2EB8FA0DAB342C79F26624
sha3_384: dabdb6233e47f6ddf020f5c98d827085799c7631406311aa974a22cdb47862d7ed2bab588f7ae94c3a4757d66fcb0f15
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-10-02 05:04:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: West London
FileDescription: Setup For TerraTech
FileVersion: 1.0.0
LegalCopyright: © West London
ProductName: TerraTech
ProductVersion: 1.4.12
Translation: 0x0000 0x04b0

NSIS:Loderka-AS [PUP] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
SangforTrojan.Win32.Agent.V6to
ESET-NOD32multiple detections
CynetMalicious (score: 100)
AvastNSIS:Loderka-AS [PUP]
DrWebAdware.Downware.20338
GoogleDetected
IkarusPUA.INNO.RePack
MaxSecureTrojan.Malware.218664370.susgen
FortinetRiskware/NDAoF
AVGNSIS:Loderka-AS [PUP]
DeepInstinctMALICIOUS

How to remove NSIS:Loderka-AS [PUP]?

NSIS:Loderka-AS [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment