PUA

NSIS:Loderka-AU [PUP] information

Malware Removal

The NSIS:Loderka-AU [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Loderka-AU [PUP] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine NSIS:Loderka-AU [PUP]?


File Info:

name: 5349D5F7C0F214BA504C.mlw
path: /opt/CAPEv2/storage/binaries/5ebb40139b470a6936835a4ce52ad23772f1ffd529c2c6e9f3a72ce2ec3dcb96
crc32: D8EB054D
md5: 5349d5f7c0f214ba504c09bd9c1a78a0
sha1: 6064e6751f3f8199012525ebf1bb2d4952255026
sha256: 5ebb40139b470a6936835a4ce52ad23772f1ffd529c2c6e9f3a72ce2ec3dcb96
sha512: 47fbeb71672b56bb485bd7f4f660b42f3a4c96f3a9dc1ca5abca3c38845f3f08e8eb8b6f8e0d6419591ac7bfb4ba6912d4a96539d73992bae3020dee92ea5688
ssdeep: 49152:US4af3w19akLp47a64smGkeSkAcXDIUKnriQvtHsnplj4NhWbGvHo9X+fbP4rG53:h4af3w19ak14u6BmG7tzIUKneQv9Sd4n
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121E51252F7C24272DAFC4DB9D05780659D399D788EE760663EF8C24F8D742E09A3E920
sha3_384: 9a1f3f0a1fd35db24497769a086dccea6d1aee38ff55a100cfa9ded97e648b03814e6e68a834eb170aa25d90e1158f8a
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-10-02 05:04:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: CarX Technologies
FileDescription: Setup For CarX Drift Racing Online
FileVersion: 1.0.0
LegalCopyright: © CarX Technologies
ProductName: CarX Drift Racing Online
ProductVersion: 2.14.3
Translation: 0x0000 0x04b0

NSIS:Loderka-AU [PUP] also known as:

BkavW32.AIDetectMalware
SangforPUP.Win32.Agent.Vnu3
CrowdStrikewin/grayware_confidence_60% (D)
ESET-NOD32multiple detections
AvastNSIS:Loderka-AU [PUP]
DrWebAdware.Downware.20335
IkarusPUA.INNO.RePack
GoogleDetected
MalwarebytesGeneric.Malware/Suspicious
MaxSecureTrojan.Malware.218664370.susgen
FortinetRiskware/NDAoF
AVGNSIS:Loderka-AU [PUP]
DeepInstinctMALICIOUS

How to remove NSIS:Loderka-AU [PUP]?

NSIS:Loderka-AU [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment