PUA

NSIS:Loderka-AU [PUP] removal

Malware Removal

The NSIS:Loderka-AU [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Loderka-AU [PUP] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine NSIS:Loderka-AU [PUP]?


File Info:

name: E32CBEE3D96B4019415B.mlw
path: /opt/CAPEv2/storage/binaries/7d8e1a9c029c8b016dfdc6071c6f82ee0dcb8d87c2f1da1ae33f12b664922fe0
crc32: 76689FB0
md5: e32cbee3d96b4019415b67979f376fb3
sha1: 72eda908912bd334c49241a36e7e4261564f6b1f
sha256: 7d8e1a9c029c8b016dfdc6071c6f82ee0dcb8d87c2f1da1ae33f12b664922fe0
sha512: 294659ad4addbdc8d473454bd4b7dde7cbc48fc668b4f2d43a7585d75d9a323c29a012575f76b72102c488e323e3741aee36d4e6b2255ef3ab634c6800e860c1
ssdeep: 49152:XDaDBi/kXs+1H1HHA7plj4NhWJfa78vHo96iAvkUxD6m66hDB:mtisXs+JZud4N8rv26cUxDF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18DB52316F3C304B2C5382B7C8CA484549E277DA859E2445F2DBDF54E95F83C27C3AAA5
sha3_384: a6d34627d06f9b00c89b4744f67d2a002d6da0d6eb572045add639ee97ab5c342208bff2fe7f1db1a783802c06e2e1bd
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-10-02 05:04:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Treyarch
FileDescription: Setup For Call of Duty World at War
FileVersion: 1.0.0
LegalCopyright: © Treyarch
ProductName: Call of Duty World at War
ProductVersion: 1.7.1263
Translation: 0x0000 0x04b0

NSIS:Loderka-AU [PUP] also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
SangforPUP.Win32.Agent.Vdh3
CrowdStrikewin/grayware_confidence_90% (W)
ESET-NOD32multiple detections
AvastNSIS:Loderka-AU [PUP]
DrWebAdware.Downware.20335
IkarusPUA.INNO.RePack
GoogleDetected
MalwarebytesGeneric.Malware/Suspicious
FortinetRiskware/NDAoF
AVGNSIS:Loderka-AU [PUP]
DeepInstinctMALICIOUS

How to remove NSIS:Loderka-AU [PUP]?

NSIS:Loderka-AU [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment