Malware

Mal/Dloadr-AO removal guide

Malware Removal

The Mal/Dloadr-AO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Dloadr-AO virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mal/Dloadr-AO?


File Info:

name: 6B7454E0308975813BC7.mlw
path: /opt/CAPEv2/storage/binaries/521fe51c4a7dc921bd943fbcb2ba6aa3a3228d61df84cd900ece8c14c1d157b7
crc32: 36FAE62A
md5: 6b7454e0308975813bc76c76ca16697d
sha1: 237410b703986247e1afc7dffe2d72baba66716e
sha256: 521fe51c4a7dc921bd943fbcb2ba6aa3a3228d61df84cd900ece8c14c1d157b7
sha512: 6f6abaa4029ac336c2e031d8802a00f2ae4ba75125d1707ae406cb0bd29b2b1f3986372b885220e5b808259425cbad79c3446aa246cc8ac79f7c82e568eb8645
ssdeep: 3072:BwRLhmqfiRYrap4zBoc0QafBYFCeCfomQa2RWI/9fNTdrN0qmG8kIkUu9uHz+Ghi:ch4maTfiZnmB2RP/LTr0Nrk19uSh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D44025A7684C816D04884B0CC6BCFF86B21BCF68F41972736E23B1FBDB2A456C5D856
sha3_384: cfc25bb581afeabc4ef5b730475317b58c5c28963ddfde527504b59d50c355af08f394fcbb86abdfb72c4b83910b8cc1
ep_bytes: 9060e803000000e9eb045d4555c3e801
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Mal/Dloadr-AO also known as:

CyrenCloudW32/ABRisk.HVTQ-9261:51:100:105.521FE51C!Threatlookup
BkavW32.Common.A8C3B746
LionicTrojan.Win32.Generic.4!c
MalwarebytesMachineLearning/Anomalous.100%
SangforTrojan.Win32.Agent.Vl3f
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanDownloader:Win32/Dloadr.52e9b41b
K7GWRiskware ( 0040eff71 )
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
AvastWin32:Malware-gen
TencentWin32.Trojan-Downloader.Generic.Swhl
SophosMal/Dloadr-AO
Trapminemalicious.high.ml.score
VaristW32/ABRisk.HVTQ-9261
Antiy-AVLTrojan[Downloader]/Win32.Generic
KingsoftWin32.Troj.Unknown.a
ZoneAlarmUDS:DangerousObject.Multi.Generic
GoogleDetected
VBA32suspected of Trojan.Downloader.gen
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H07H423
SentinelOneStatic AI – Suspicious PE
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Mal/Dloadr-AO?

Mal/Dloadr-AO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment