PUA

NSIS:Loderka-AU [PUP] (file analysis)

Malware Removal

The NSIS:Loderka-AU [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Loderka-AU [PUP] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine NSIS:Loderka-AU [PUP]?


File Info:

name: EA275FA44E04F20CD36C.mlw
path: /opt/CAPEv2/storage/binaries/a900c5918297c1857591c5cccc7aad615ef8e7a8cb86efe04ef06e3f7c2a18d6
crc32: 6FD6A891
md5: ea275fa44e04f20cd36c2b375a6808e4
sha1: 9b22fc3b275e8e3a27c68b03cbdd5661442a47ee
sha256: a900c5918297c1857591c5cccc7aad615ef8e7a8cb86efe04ef06e3f7c2a18d6
sha512: debcfe21919d8eef6df0f662ecb208688f3984b05cb6bc69454986ab78a868c2cd1bcaadec2fc6c93a8da56e4d71f55b6a2c942c0ffcd62505e0aca7e60ed76a
ssdeep: 49152:dpzZ4JAiua5plj4NhWdvHo9FkT9P/hw76MYIEvL:/mvnd4N8dv2qM9OL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B8951242AAC7C4B5DD2409B8C4A690F05C376CB9D8E62417ADF9FE0E7A3E6853C35463
sha3_384: e38113e7fe22cc54f7b690f4e6d10e2943fc23aa8d2e64c646ad53cdd526f16ccf26421cecbd4f657a820ac945ff5b26
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-10-02 05:04:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Valve
FileDescription: Setup For Counter-Strike Global Offensive
FileVersion: 1.0.0
LegalCopyright: © Valve
ProductName: Counter-Strike Global Offensive
ProductVersion: 1.38.3.4
Translation: 0x0000 0x04b0

NSIS:Loderka-AU [PUP] also known as:

BkavW32.AIDetectMalware
DrWebAdware.Downware.20335
SangforPUP.Win32.Agent.Va2i
CrowdStrikewin/grayware_confidence_70% (W)
ESET-NOD32multiple detections
CynetMalicious (score: 100)
AvastNSIS:Loderka-AU [PUP]
IkarusPUA.INNO.RePack
GoogleDetected
MalwarebytesGeneric.Malware/Suspicious
MaxSecureTrojan.Malware.218664370.susgen
FortinetRiskware/NDAoF
AVGNSIS:Loderka-AU [PUP]
DeepInstinctMALICIOUS

How to remove NSIS:Loderka-AU [PUP]?

NSIS:Loderka-AU [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment