Trojan

Should I remove “NSIS/TrojanDownloader.Adload.CC”?

Malware Removal

The NSIS/TrojanDownloader.Adload.CC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS/TrojanDownloader.Adload.CC virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

st.youfile.org
dl.mp3arhiv.net
www.bing.com

How to determine NSIS/TrojanDownloader.Adload.CC?


File Info:

crc32: BCF65816
md5: 0c9985f9e90bbda5cf34e8a2ebbcb5b2
name: 0C9985F9E90BBDA5CF34E8A2EBBCB5B2.mlw
sha1: 363aead04799786c0ec7b241c9dee1ffbbaf4144
sha256: d7fc8b65f73d16c6d41ec85b35fc993c5e42c63e4e9cc0d8ea9ba068656d9383
sha512: 79232042ecd04a87e8f2ca200551e9c8e23df4c332b1dab453e8fc3cc078a76d16fb253434b38b39d0f49b8be8ff8e5d673efefaed1a128cb951af77900a1919
ssdeep: 3072:CX7DItrfaocyTgfsqQOlJsRF+OayNXlHHz8RZoIUYYWUYOYwYOOYUSUJd+YWYLid:CsaocyLCyA2HIvDpD7xX3yrly12
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

NSIS/TrojanDownloader.Adload.CC also known as:

MicroWorld-eScanAdware.GenericKD.36291942
FireEyeAdware.GenericKD.36291942
McAfeeArtemis!0C9985F9E90B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 004f7e561 )
BitDefenderAdware.GenericKD.36291942
K7GWTrojan-Downloader ( 004f7e561 )
Cybereasonmalicious.047997
CyrenW32/Trojan.IJML-6561
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:Downloader.Win32.Arload.a
AlibabaDownloader:Win32/Arload.ba92be45
NANO-AntivirusRiskware.Nsis.Adw.ebttih
RisingDownloader.NSIS/Adload!1.ACCB (CLASSIC)
Ad-AwareAdware.GenericKD.36291942
EmsisoftApplication.AdLoad (A)
F-SecureHeuristic.HEUR/AGEN.1127157
DrWebAdware.Downware.13430
McAfee-GW-EditionArtemis
SophosGeneric PUA DG (PUA)
AviraHEUR/AGEN.1127157
Antiy-AVLGrayWare[Downloader]/Win32.Adload.gen
MicrosoftPUA:Win32/Creprote
GridinsoftAdware.Win32.Downloader.oa
ArcabitAdware.Generic.D229C566
ZoneAlarmnot-a-virus:Downloader.Win32.Arload.a
GDataAdware.GenericKD.36291942
CynetMalicious (score: 85)
MAXmalware (ai score=69)
MalwarebytesAdware.AdLoad
ESET-NOD32NSIS/TrojanDownloader.Adload.CC
TrendMicro-HouseCallTROJ_GEN.R002H0CB321
TencentNsis.Trojan-downloader.Adload.Hzd
FortinetRiskware/Adload
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDownloader.Generic.HoMASOUA

How to remove NSIS/TrojanDownloader.Adload.CC?

NSIS/TrojanDownloader.Adload.CC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment