PUA

NSIS:Loderka-AU [PUP] malicious file

Malware Removal

The NSIS:Loderka-AU [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Loderka-AU [PUP] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine NSIS:Loderka-AU [PUP]?


File Info:

name: 6D1D4651A05FB7D150C7.mlw
path: /opt/CAPEv2/storage/binaries/0d75e67e6346a1ae096ced77bec91f55e516a01e063c9a921679021dfe9c51a6
crc32: 9F55770B
md5: 6d1d4651a05fb7d150c7cd99e41f7bd9
sha1: 98f3be7046a66f97b9788a8f551cc153944d981b
sha256: 0d75e67e6346a1ae096ced77bec91f55e516a01e063c9a921679021dfe9c51a6
sha512: d209f9f5e873ccdb1110335714b81d84701dde9964a78f99f2b4037a6649e2ce198085d329c32e9535a64c980ccda29b7c3ef57486e6c57688065239d5ca2fef
ssdeep: 49152:7ftB3UY09ojolY78Xplj4NhW2rWvHo9MA1Tazw9YbsoI:ZBkYrolw8Zd4N82rWv2fpaAk1I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0B5014636A288B7C252227C6995F77C4D265FF429E6C6427CF0EC8F7970B893C395A0
sha3_384: 4e7b4e7624372b8dd9b3e4bef440345ddcf044fe72e172f6bfd33c106620b37a3a3cdc15a19f1f66c8f2248a639299fe
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-10-02 05:04:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Running With Scissors
FileDescription: Setup For POSTAL 4
FileVersion: 1.0.0
LegalCopyright: © Running With Scissors
ProductName: POSTAL 4
ProductVersion: 0.5.0
Translation: 0x0000 0x04b0

NSIS:Loderka-AU [PUP] also known as:

BkavW32.AIDetectMalware
MalwarebytesGeneric.Malware/Suspicious
SangforPUP.Win32.Agent.V7r4
CrowdStrikewin/grayware_confidence_60% (D)
ESET-NOD32multiple detections
AvastNSIS:Loderka-AU [PUP]
DrWebAdware.Downware.20346
IkarusPUA.INNO.RePack
CynetMalicious (score: 100)
MaxSecureTrojan.Malware.218664370.susgen
AVGNSIS:Loderka-AU [PUP]
DeepInstinctMALICIOUS

How to remove NSIS:Loderka-AU [PUP]?

NSIS:Loderka-AU [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment