PUA

How to remove “NSIS:Loderka-AU [PUP]”?

Malware Removal

The NSIS:Loderka-AU [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Loderka-AU [PUP] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine NSIS:Loderka-AU [PUP]?


File Info:

name: F0A93E72E51BEEAF484D.mlw
path: /opt/CAPEv2/storage/binaries/23b287a80cb805f019a00b939932314af6576219724f4fb68d39e8fb2cb07aea
crc32: 6226C251
md5: f0a93e72e51beeaf484d49b1cf153441
sha1: 154795bf59a69bbef980a86ee07b6f737ea0e8fa
sha256: 23b287a80cb805f019a00b939932314af6576219724f4fb68d39e8fb2cb07aea
sha512: 3ed44c40f5f65ea7e0959d9886560b55d2a2247df5fa94d275835c6460d712ad665ce4c5cfed1993274b07a99146e368731c04ba4207c7a14312cea0ea179592
ssdeep: 49152:YNo9sFaGWplj4NhWXvHo93rxjAarq8IGcdefh:N9sFvmd4N8Xv23huQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132852343F7C780B2D6A509B8DC569084AD277D642DE2606E7CF8F60F09B4282697FDB1
sha3_384: 1ef0dc5fabbb337b34add2dd0b0b680e250481cdb5abc86188310aa97716ab151f21cb98b89134ac09112db92c0478dd
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-10-02 05:04:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Klei Entertainment
FileDescription: Setup For Dont Starve
FileVersion: 1.0.04
LegalCopyright: © Klei Entertainment
ProductName: Dont Starve
ProductVersion: 52.08.644
Translation: 0x0000 0x04b0

NSIS:Loderka-AU [PUP] also known as:

BkavW32.Common.64676C65
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.BadFile.tc
McAfeeArtemis!F0A93E72E51B
MalwarebytesGeneric.Malware/Suspicious
SangforPUP.Win32.Agent.Vqkp
CrowdStrikewin/grayware_confidence_60% (W)
ESET-NOD32multiple detections
AvastNSIS:Loderka-AU [PUP]
DrWebAdware.Downware.20335
IkarusPUA.INNO.RePack
Cylanceunsafe
FortinetW32/NDAoF
AVGNSIS:Loderka-AU [PUP]
DeepInstinctMALICIOUS

How to remove NSIS:Loderka-AU [PUP]?

NSIS:Loderka-AU [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment