Malware

Downloader.Win32.AdLoad.uyjw malicious file

Malware Removal

The Downloader.Win32.AdLoad.uyjw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.AdLoad.uyjw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Downloader.Win32.AdLoad.uyjw?


File Info:

name: 3083ACDAC39BA590D6D7.mlw
path: /opt/CAPEv2/storage/binaries/624b958ee52426dec764c16212879bba851f7f73b0d6639c3de4f8efa226bf5f
crc32: 7E55406C
md5: 3083acdac39ba590d6d7cc78f35f2567
sha1: 4d4e75566f9d04f4737c7f3c76d15ed064b698b4
sha256: 624b958ee52426dec764c16212879bba851f7f73b0d6639c3de4f8efa226bf5f
sha512: 935d3df4f60876d83df373a24ca283351c06049dde5ea75b4d515dd6503b71788755554b28c39a1c72e94680f8aa59f734d26760f7d0761b1905522229547631
ssdeep: 12288:UTOcCf6yNVEH66eDlBH/eSaslMdfFMfd8P:UTOpVVq66gasWZTP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9A4122077E5C4FDD2E105338C959AA453BEFA710F19888B57980E0E9EB1BC5FB3A251
sha3_384: 14b02e411c8047b819b7442cec30d1804f502601cfa6510a859489798e32b3a3e1a4867db74d03add3647ff33baeb91e
ep_bytes: 558bec6aff68284c4100686023410064
timestamp: 2011-04-28 11:38:20

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
LegalCopyright: Copyright © 2005-2010 Oleg N. Scherbakov
ProductName: 7-Zip SFX
ProductVersion: 1.4.1.2100
FileVersion: 1.4.1.2100
CompiledBy: Compiled by SFXMaker
Translation: 0x0000 0x04b0
InternalName: 7ZSfxMod
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: April 28, 2011

Downloader.Win32.AdLoad.uyjw also known as:

LionicRiskware.Win32.AdLoad.1!c
McAfeeArtemis!3083ACDAC39B
CylanceUnsafe
SangforDownloader.Win32.AdLoad.Vhz5
VirITTrojan.Win32.Dnldr22.CRCZ
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_GEN.R002H0CBI22
Paloaltogeneric.ml
Kasperskynot-a-virus:Downloader.Win32.AdLoad.uyjw
AlibabaDownloader:Win32/AdLoad.803e1f10
AvastFileRepMalware [Trj]
ComodoApplicUnwnt@#28na2lzq6ohlk
DrWebTrojan.DownLoader22.46721
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.gc
SophosGeneric PUA EN (PUA)
APEXMalicious
WebrootPUA.Gen
KingsoftWin32.Troj.DownAdLoad.uy.(kcloud)
ViRobotAdware.Adload.457915
ZoneAlarmnot-a-virus:UDS:Downloader.Win32.AdLoad.uyjw
MicrosoftTrojan:Win32/Occamy.C62
VBA32Downloader.AdLoad
MalwarebytesMalware.AI.4181426690
YandexPUA.Downloader!bTQ3OTET8RQ
MaxSecureTrojan.Malware.7175239.susgen
FortinetRiskware/Adload
AVGFileRepMalware [Trj]
PandaTrj/CI.A

How to remove Downloader.Win32.AdLoad.uyjw?

Downloader.Win32.AdLoad.uyjw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment