PUA

How to remove “NSIS:Loderka-AU [PUP]”?

Malware Removal

The NSIS:Loderka-AU [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Loderka-AU [PUP] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine NSIS:Loderka-AU [PUP]?


File Info:

name: 2E36E5819AF615B82BA9.mlw
path: /opt/CAPEv2/storage/binaries/6c983e9ecc2f532d7a7783425d6db9a8268961a3c8042c07224d338277e017f5
crc32: AC6CFD8F
md5: 2e36e5819af615b82ba967934af81e17
sha1: 13c7f0b06bf788360f45b12d99ef4c7e5062a3aa
sha256: 6c983e9ecc2f532d7a7783425d6db9a8268961a3c8042c07224d338277e017f5
sha512: ee7f614e6fc9677e0cced488b196e604419f628ca2808e11f1d71751994d34d44c62aab7ceae31fe34b73c832bc979ff95e4152ece0ae1ea1e77395cc282dc52
ssdeep: 49152:r0ZKV1EkXHMMboFbXT3plj4NhW9vHo9iKQiG7pwbVcmh7h:qiOksMboFVd4N89v2H/G7yRh7h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18EC51202B3C2D932D9691678C8A6C3F06E22BC64DAF251176DF8FD1F79362D02C765A1
sha3_384: 356824970b24f5b36796cf8524e53ebf81b6db5c1c5a851c11842b463c3364bf648a70352df73d6211cc1581fd66cf50
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-10-02 05:04:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: KOEI TECMO GAMES CO., LTD.
FileDescription: Setup For Nioh 2 - The Complete Edition
FileVersion: 1.0.04
LegalCopyright: © KOEI TECMO GAMES CO., LTD.
ProductName: Nioh 2 - The Complete Edition
ProductVersion: 1.28.074
Translation: 0x0000 0x04b0

NSIS:Loderka-AU [PUP] also known as:

BkavW32.AIDetectMalware
AVGNSIS:Loderka-AU [PUP]
MalwarebytesGeneric.Malware/Suspicious
SangforPUP.Win32.Agent.Vua1
CrowdStrikewin/grayware_confidence_60% (D)
SymantecPUA.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
CynetMalicious (score: 100)
AvastNSIS:Loderka-AU [PUP]
DrWebAdware.Downware.20335
SophosGeneric Reputation PUA (PUA)
GoogleDetected
Cylanceunsafe
IkarusPUA.INNO.RePack
MaxSecureTrojan.Malware.218664370.susgen
DeepInstinctMALICIOUS

How to remove NSIS:Loderka-AU [PUP]?

NSIS:Loderka-AU [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment