Malware

Application.AdLoad (A) removal tips

Malware Removal

The Application.AdLoad (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.AdLoad (A) virus can do?

  • Presents an Authenticode digital signature
  • Attempts to connect to a dead IP:Port (9 unique times)
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Detects VirtualBox through the presence of a window
  • Detects VirtualBox using WNetGetProviderName trick
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Likely virus infection of existing system binary
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a file
  • Detects VirtualBox through the presence of a registry key
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Created a service that was not started

Related domains:

z.whorecord.xyz
a.tomx.xyz
chistilka.com
api.amplitude.com
www.google-analytics.com
chistilka.ru
stat2.chistilka.com
apps.identrust.com
update.chistilka.com
crt.sectigo.com
crt.usertrust.com
pay.chistilka.com

How to determine Application.AdLoad (A)?


File Info:

crc32: 369CC617
md5: 4ff9817646266fb699edf41cec617de2
name: bin-2.21.241.exe
sha1: 7843a77e0c8d15c1c879a791c8e73f0a2874257b
sha256: b60bfb5f8596bc7d8937728f9014dacf5ec10a5c2da8a2bb95b6fe10c4f28049
sha512: d48bb47aac80a05b06bd2b56cc8a8c30e665735bf88aab6428dc9b9ce9d1cef1566b02b21b53ecf6324ae85fa2be9352b84f085b648c734b22ad57353903e47f
ssdeep: 98304:3pXxRVxVrbG3tNBnL6TbPMFMmT4PU7MpT4PU7MIPHiN/YhGSH:ZxmtNBnFPN/IGSH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: x427x438x441x442x438x43bx43ax430.exe
FileVersion: 2.21.241
CompanyName:
LegalTrademarks1:
LegalTrademarks2:
ProductName: x427x438x441x442x438x43bx43ax430
ProductVersion: 2.21.241
FileDescription: x41fx440x43ex433x440x430x43cx43cx43dx43ex435 x43ex431x435x441x43fx435x447x435x43dx438x435 x434x43bx44f x441x43ex434x435x440x436x430x43dx438x44f x43ax43ex43cx43fx44cx44ex442x435x440x430 x432 x447x438x441x442x43ex442x435.
OriginalFilename: x427x438x441x442x438x43bx43ax430.exe
Translation: 0x0419 0x04b0

Application.AdLoad (A) also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.41660116
FireEyeGeneric.mg.4ff9817646266fb6
CAT-QuickHealTrojan.GenericRI.S7512349
ALYacTrojan.GenericKD.41660116
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.41660116
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataTrojan.GenericKD.41660116
Kasperskynot-a-virus:HEUR:Downloader.Win32.Generic
NANO-AntivirusRiskware.Win32.Chistilka.gaoqkc
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.41660116
SophosVKontakteDJ (PUA)
ComodoApplicUnwnt@#6bj5k9uhfd8n
F-SecureTrojan.TR/RedCap.zbxqq
DrWebTrojan.DownLoader30.12814
ZillyaTrojan.Khalesi.Win32.11677
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
MaxSecureTrojan.Malware.12126263.susgen
EmsisoftApplication.AdLoad (A)
CyrenW32/Trojan.QUQR-4183
JiangminHoax.PCChist.y
WebrootW32.Adware.Gen
AviraTR/RedCap.zbxqq
Antiy-AVLGrayWare/Win32.Generic
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D27BAED4
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.Generic
MicrosoftPUA:Win32/Conduit
AhnLab-V3PUP/Win32.Helper.R289155
McAfeeChistilka
MAXmalware (ai score=81)
VBA32Trojan.Downloader
MalwarebytesPUP.Optional.Chistilka
ESET-NOD32a variant of Win32/Chistilka.B potentially unwanted
RisingTrojan.Wacatac!8.10C01 (CLOUD)
YandexTrojan.Khalesi!
IkarusTrojan.PSW.Agent
FortinetW32/PCChist.C00D!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
Qihoo-360Win32/Virus.Downloader.c05

How to remove Application.AdLoad (A)?

Application.AdLoad (A) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment