Categories: Malware

Application.AdLoad (A) removal tips

The Application.AdLoad (A) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.AdLoad (A) virus can do?

  • Presents an Authenticode digital signature
  • Attempts to connect to a dead IP:Port (9 unique times)
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Detects VirtualBox through the presence of a window
  • Detects VirtualBox using WNetGetProviderName trick
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Likely virus infection of existing system binary
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a device
  • Detects VirtualBox through the presence of a file
  • Detects VirtualBox through the presence of a registry key
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Created a service that was not started

Related domains:

z.whorecord.xyz
a.tomx.xyz
chistilka.com
api.amplitude.com
www.google-analytics.com
chistilka.ru
stat2.chistilka.com
apps.identrust.com
update.chistilka.com
crt.sectigo.com
crt.usertrust.com
pay.chistilka.com

How to determine Application.AdLoad (A)?


File Info:

crc32: 369CC617md5: 4ff9817646266fb699edf41cec617de2name: bin-2.21.241.exesha1: 7843a77e0c8d15c1c879a791c8e73f0a2874257bsha256: b60bfb5f8596bc7d8937728f9014dacf5ec10a5c2da8a2bb95b6fe10c4f28049sha512: d48bb47aac80a05b06bd2b56cc8a8c30e665735bf88aab6428dc9b9ce9d1cef1566b02b21b53ecf6324ae85fa2be9352b84f085b648c734b22ad57353903e47fssdeep: 98304:3pXxRVxVrbG3tNBnL6TbPMFMmT4PU7MpT4PU7MIPHiN/YhGSH:ZxmtNBnFPN/IGSHtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: InternalName: x427x438x441x442x438x43bx43ax430.exeFileVersion: 2.21.241CompanyName: LegalTrademarks1: LegalTrademarks2: ProductName: x427x438x441x442x438x43bx43ax430ProductVersion: 2.21.241FileDescription: x41fx440x43ex433x440x430x43cx43cx43dx43ex435 x43ex431x435x441x43fx435x447x435x43dx438x435 x434x43bx44f x441x43ex434x435x440x436x430x43dx438x44f x43ax43ex43cx43fx44cx44ex442x435x440x430 x432 x447x438x441x442x43ex442x435.OriginalFilename: x427x438x441x442x438x43bx43ax430.exeTranslation: 0x0419 0x04b0

Application.AdLoad (A) also known as:

Bkav W32.AIDetectVM.malware
MicroWorld-eScan Trojan.GenericKD.41660116
FireEye Generic.mg.4ff9817646266fb6
CAT-QuickHeal Trojan.GenericRI.S7512349
ALYac Trojan.GenericKD.41660116
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Trojan.GenericKD.41660116
K7GW Riskware ( 0040eff71 )
Symantec ML.Attribute.HighConfidence
APEX Malicious
GData Trojan.GenericKD.41660116
Kaspersky not-a-virus:HEUR:Downloader.Win32.Generic
NANO-Antivirus Riskware.Win32.Chistilka.gaoqkc
Avast Win32:Malware-gen
Ad-Aware Trojan.GenericKD.41660116
Sophos VKontakteDJ (PUA)
Comodo ApplicUnwnt@#6bj5k9uhfd8n
F-Secure Trojan.TR/RedCap.zbxqq
DrWeb Trojan.DownLoader30.12814
Zillya Trojan.Khalesi.Win32.11677
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.TrojanAitInject.tc
MaxSecure Trojan.Malware.12126263.susgen
Emsisoft Application.AdLoad (A)
Cyren W32/Trojan.QUQR-4183
Jiangmin Hoax.PCChist.y
Webroot W32.Adware.Gen
Avira TR/RedCap.zbxqq
Antiy-AVL GrayWare/Win32.Generic
Endgame malicious (high confidence)
Arcabit Trojan.Generic.D27BAED4
ZoneAlarm not-a-virus:HEUR:Downloader.Win32.Generic
Microsoft PUA:Win32/Conduit
AhnLab-V3 PUP/Win32.Helper.R289155
McAfee Chistilka
MAX malware (ai score=81)
VBA32 Trojan.Downloader
Malwarebytes PUP.Optional.Chistilka
ESET-NOD32 a variant of Win32/Chistilka.B potentially unwanted
Rising Trojan.Wacatac!8.10C01 (CLOUD)
Yandex Trojan.Khalesi!
Ikarus Trojan.PSW.Agent
Fortinet W32/PCChist.C00D!tr
AVG Win32:Malware-gen
Panda Trj/Genetic.gen
Qihoo-360 Win32/Virus.Downloader.c05

How to remove Application.AdLoad (A)?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

1 week ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

1 week ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

1 week ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

1 week ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

1 week ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

1 week ago