PUA

NSIS:Loderka-BC [PUP] removal instruction

Malware Removal

The NSIS:Loderka-BC [PUP] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Loderka-BC [PUP] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine NSIS:Loderka-BC [PUP]?


File Info:

name: CC3158C39C7E9AEAD801.mlw
path: /opt/CAPEv2/storage/binaries/7d511971661ce96477fe028b92bb89c027aa0a0b2098908242934831c8125ae5
crc32: 479240DC
md5: cc3158c39c7e9aead801fe2e77b7f8b3
sha1: 784e6eedd9f702b8569497cc0579341e17c931b6
sha256: 7d511971661ce96477fe028b92bb89c027aa0a0b2098908242934831c8125ae5
sha512: 1cafab1f7cecebe168501bb79f8bfbab30b1c532f2572099806713044e982402e6575774f17dfd8824425400d0b8e5a717dff28922a6ac9cc6690c562ee59e69
ssdeep: 49152:8DeRCs4hI6LL6Fplj4NhWMchvHo9oS7j7rgnVaCqSfcdI:cs4hI6Lgd4N8Mchv23j0aCq4c+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FB512C382EFA0F1F954E6399143CE9FED83684913F924542E77D50E9AB438B35709A8
sha3_384: be22340eadd803f5eda7769dba0b67d466e8a0572296e6d5a6257027ad656cf915ff57dd171c5f6c1196d9242f0f1446
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2012-10-02 05:04:04

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Ubisoft Montreal
FileDescription: Setup For Assassins Creed Odyssey
FileVersion: 1.0.04
LegalCopyright: © Ubisoft Montreal
ProductName: Assassins Creed Odyssey
ProductVersion: 1.5.34
Translation: 0x0000 0x04b0

NSIS:Loderka-BC [PUP] also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKD.66371900
Cylanceunsafe
SangforTrojan.Win32.Agent.Vbev
CrowdStrikewin/grayware_confidence_70% (W)
ArcabitTrojan.Generic.D3F4C13C
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
BitDefenderTrojan.GenericKD.66371900
AvastNSIS:Loderka-BC [PUP]
EmsisoftTrojan.GenericKD.66371900 (B)
DrWebAdware.Downware.20338
VIPRETrojan.GenericKD.66371900
SophosMal/Generic-S
IkarusPUA.INNO.RePack
GDataTrojan.GenericKD.66371900
ALYacTrojan.GenericKD.66371900
MalwarebytesNeshta.Virus.FileInfector.DDS
FortinetPossibleThreat.FORTIEDR.H
AVGNSIS:Loderka-BC [PUP]
DeepInstinctMALICIOUS

How to remove NSIS:Loderka-BC [PUP]?

NSIS:Loderka-BC [PUP] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment