Malware

AdWare.AdLoad (file analysis)

Malware Removal

The AdWare.AdLoad is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.AdLoad virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

Related domains:

w-tf.ru

How to determine AdWare.AdLoad?


File Info:

name: CA69521D609D8E0AA8F2.mlw
path: /opt/CAPEv2/storage/binaries/22d8e285ceb3770ee884afe1bb2996ea8ad5469184aa55d91516bc95740ac3b4
crc32: D3F1074F
md5: ca69521d609d8e0aa8f225bb05458b41
sha1: cfb8b8380f0b154ef91d4211848bca44a2b6c804
sha256: 22d8e285ceb3770ee884afe1bb2996ea8ad5469184aa55d91516bc95740ac3b4
sha512: 4fcc46c9382dd7da42f5045d0991695921bd20ae8c50a866bd0a0ea9a130e8c7c96616c01b978f57a835e9931d1376c60002b7fcc9a187ba43fb72472ef5b203
ssdeep: 49152:w1XFIIOSpK7cQ8ucGVk/OGh/jVeq5AhHTLVjiER5fFGbUPM0c:jSKwDGVGOGhrrktbfcgP7c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19056126193E18315F1B32BB064F06136BA36BEBA2E115A4F63C6610D3579B86DE30377
sha3_384: 94d9f74a6829f86215603e9a27e653b69cb2b011a8f3dba29cc848883a654347d708da1643ebbc5778f9bfaa2fad5b76
ep_bytes: 558becb8081e0000e813110300c745e8
timestamp: 2016-01-31 06:14:31

Version Info:

0: [No Data]

AdWare.AdLoad also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.CTXS
FireEyeGeneric.mg.ca69521d609d8e0a
ALYacTrojan.Agent.CTXS
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaAdWare:Win32/StartSurf.f3833e75
K7GWTrojan ( 00529d5a1 )
K7AntiVirusTrojan ( 00529d5a1 )
BitDefenderThetaGen:NN.ZexaF.34294.@BW@a8QTFDhi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GEAU
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderTrojan.Agent.CTXS
NANO-AntivirusRiskware.Win32.AdLoad.exgxum
ViRobotAdware.Adload.6094336.BR
RisingTrojan.Kryptik!1.B33C (CLASSIC)
Ad-AwareTrojan.Agent.CTXS
DrWebTrojan.Zadved.779
SophosGeneric PUA MP (PUA)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1108558
Antiy-AVLTrojan/Generic.ASMalwS.2422485
GridinsoftRansom.Win32.Wacatac.sa
GDataTrojan.Agent.CTXS
AhnLab-V3Adware/Win32.AdLoad.R218933
Acronissuspicious
VBA32AdWare.AdLoad
MAXmalware (ai score=82)
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
TencentMalware.Win32.Gencirc.10ba5e78
YandexPUA.AdLoad!1+jUhn1aam4
FortinetW32/Kryptik.FWLF!tr
PandaTrj/Genetic.gen

How to remove AdWare.AdLoad?

AdWare.AdLoad removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment