PUA

NSIS:Loderka-AU [PUP] (file analysis)

Malware Removal

The NSIS:Loderka-AU [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Loderka-AU [PUP] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine NSIS:Loderka-AU [PUP]?


File Info:

name: CF75C2585CE4C1F041BD.mlw
path: /opt/CAPEv2/storage/binaries/68b926eadbb117ee0003904344e53d0710d7ba56a38117d2267631e554ea6b1d
crc32: 1F40A077
md5: cf75c2585ce4c1f041bd20ab4834f1f3
sha1: 4fad15e75d3dd84099f0e96fb28b095239b3f020
sha256: 68b926eadbb117ee0003904344e53d0710d7ba56a38117d2267631e554ea6b1d
sha512: abf285a31ee2a2e053709d54983cb2cd4560d9f44e9ceb49889faab6e2e94781d85e9e563959899e5991f6ff3d22e1cfe7888a8f0a25d75dfe0da1e3870ce23d
ssdeep: 49152:uuTsjQsbVmkycYvAE9afplj4NhWmsvHo9vI0jpC2cG7RwPM:zQQsbVepaBd4N8msv2BVj/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D3B52343F3C34137F5691679C8A98080AE23FEA92AE230665CFCD54F06B93C52975EB5
sha3_384: a1d4fd73c4e151b92544d7e4a363d16aa153dd422ef44eb9fe1fc9d827bd1eaf1926985cacb6775da9b58b569082de86
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-10-02 05:04:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: PlayStation Mobile
FileDescription: Setup For Horizon Zero Dawn
FileVersion: 1.0.0
LegalCopyright: © PlayStation Mobile
ProductName: Horizon Zero Dawn
ProductVersion: 1.11
Translation: 0x0000 0x04b0

NSIS:Loderka-AU [PUP] also known as:

BkavW32.AIDetectMalware
DrWebAdware.Downware.20335
SangforPUP.Win32.Agent.Vt4w
CrowdStrikewin/grayware_confidence_60% (D)
ESET-NOD32multiple detections
CynetMalicious (score: 100)
AvastNSIS:Loderka-AU [PUP]
IkarusPUA.INNO.RePack
GoogleDetected
MalwarebytesGeneric.Malware/Suspicious
FortinetRiskware/NDAoF
AVGNSIS:Loderka-AU [PUP]

How to remove NSIS:Loderka-AU [PUP]?

NSIS:Loderka-AU [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment