PUA

AdLoad (PUA) (file analysis)

Malware Removal

The AdLoad (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdLoad (PUA) virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine AdLoad (PUA)?


File Info:

crc32: BEB85FB1
md5: 7a8f609360e950758c6df1674f4ccf50
name: mini_01.exe
sha1: 7007386a308c8537fa6dbe141bb9f1076e60a4db
sha256: 193548af78cd25a267bea0472607b94cb2541939860a0f5d7a11df2b6659f790
sha512: f1424f9428b457ae22071ab0a78443b7d7e2296d7563dcfba9f464991a942c51cfeed43827274ac8ffd996037768097e4cd978c0ccaffb0c6b1dba73852141c0
ssdeep: 24576:VA1ylYc7NQDpXyrFZhU+pAk29Fcxq2tVqT4aOBtSC8fCb:dlYiNepXqhcLy/qTvtCWCb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019 x8c46x9ea6x7b14x8bb0 .Inc
InternalName: ADManage.exe
FileVersion: 2019.3.25.33
CompanyName: TODO:
ProductName: x70edx70b9x65b0x95fb
ProductVersion: 2019.3.25.33
FileDescription: x70edx70b9x65b0x95fb
OriginalFilename: ADManage.exe
Translation: 0x0804 0x04b0

AdLoad (PUA) also known as:

MicroWorld-eScanTrojan.GenericKD.32683501
McAfeeGenericRXAA-AA!7A8F609360E9
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 00551bd41 )
BitDefenderTrojan.GenericKD.32683501
K7GWTrojan-Downloader ( 00551bd41 )
ArcabitTrojan.Generic.D1F2B5ED
TrendMicroTROJ_GEN.F0CBC0UKE19
CyrenW32/Application.QLFA-3328
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Adload.NUQ
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.ComponentBased.gen
AlibabaTrojanDownloader:Win32/Adload.37db829d
ViRobotAdware.Graftor.1757400
TencentMalware.Win32.Gencirc.10b0ce16
Ad-AwareTrojan.GenericKD.32683501
EmsisoftTrojan.GenericKD.32683501 (B)
ComodoMalware@#3salz6wxl478g
F-SecureTrojan.TR/Dldr.Adload.gtsqp
ZillyaDownloader.Adload.Win32.90313
Invinceaheuristic
McAfee-GW-EditionArtemis!PUP
FortinetW32/Adload.NUJ!tr.dldr
FireEyeTrojan.GenericKD.32683501
SophosAdLoad (PUA)
IkarusTrojan-Downloader.Win32.Adload
JiangminAdWare.ComponentBased.p
WebrootW32.Adware.Gen
AviraTR/Dldr.Adload.gtsqp
MAXmalware (ai score=85)
Antiy-AVLTrojan[Downloader]/Win32.AdLoad
Endgamemalicious (high confidence)
MicrosoftPUA:Win32/CoinMiner
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.ComponentBased.gen
AhnLab-V3Adware/Win32.AdLoad.R301284
VBA32Adware.ComponentBased
ALYacTrojan.GenericKD.32683501
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.F0CBC0UKE19
RisingAdware.AdPop!1.BA31 (CLASSIC)
YandexPUA.ComponentBased!
eGambitUnsafe.AI_Score_55%
GDataTrojan.GenericKD.32683501
AVGWin32:Adware-gen [Adw]
Qihoo-360Win32/Virus.Adware.a94

How to remove AdLoad (PUA)?

AdLoad (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment