Adware

NSIS:Adware-ADT [Trj] removal

Malware Removal

The NSIS:Adware-ADT [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What NSIS:Adware-ADT [Trj] virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine NSIS:Adware-ADT [Trj]?


File Info:

name: 37DE8C9D21D1F6735BA0.mlw
path: /opt/CAPEv2/storage/binaries/fcfa45a69df1cfee9072b11e4c7d29fb4555c3e9f50cc911299c44ec793823fb
crc32: 05029B86
md5: 37de8c9d21d1f6735ba0df34251bf876
sha1: 105de6c0b797def4878b1ca76ff7178299b7e9c5
sha256: fcfa45a69df1cfee9072b11e4c7d29fb4555c3e9f50cc911299c44ec793823fb
sha512: d2ffea732cc6c6a10772835e98db5514ff4076125f004db4d9f301fdf1fa4e9e4109eef3939a34fb8768503da3bb491079ffd96a5ddee9784f10ef074a6d0a83
ssdeep: 196608:xOa1XtdrKFCQMZ44Qn4kpuW4pC6lOPDWKdEEFYrJZd3WZ:4abpKYlkMp3YPiqFYFZdmZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111A63328D89423F1F8012F790DAF031E73F9ED5C9C625AE7D9E16AA635DC9148A1C9CC
sha3_384: aba536deb22530945fd34ee133518bbe5ab2f009c5ed083258c8b71655c82186b1a20d05d62748708419729dfb755439
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

NSIS:Adware-ADT [Trj] also known as:

LionicTrojan.Win32.Adload.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.48224200
FireEyeGeneric.mg.37de8c9d21d1f673
ALYacTrojan.GenericKD.48224200
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Adload.gen
K7AntiVirusTrojan ( 0056d6c61 )
AlibabaAdWare:Win32/AdLoad.cb352b94
K7GWTrojan ( 0056d6c61 )
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/Adload.FE.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32NSIS/TrojanDownloader.Adload.CX
APEXMalicious
AvastNSIS:Adware-ADT [Trj]
ClamAVWin.Malware.Agen-9781592-0
KasperskyHEUR:Trojan-Downloader.Win32.Adload.gen
BitDefenderTrojan.GenericKD.48224200
NANO-AntivirusTrojan.Nsis.Downloader.hzmrkk
TencentNsis.Trojan-downloader.Adload.Lmli
Ad-AwareTrojan.GenericKD.48224200
SophosMal/Generic-S
DrWebTrojan.DownLoader32.58598
ZillyaDownloader.Adload.Win32.112965
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.tc
EmsisoftTrojan.GenericKD.48224200 (B)
Paloaltogeneric.ml
GDataTrojan.GenericKD.48224200
AviraHEUR/AGEN.1233711
ViRobotTrojan.Win32.Z.Adload.10274907
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!37DE8C9D21D1
MAXmalware (ai score=85)
VBA32TrojanDownloader.Adload
MalwarebytesTrojan.AdLoad
TrendMicro-HouseCallTROJ_GEN.R002H0CB122
SentinelOneStatic AI – Suspicious PE
FortinetNSIS/Adload.AD81!tr
AVGNSIS:Adware-ADT [Trj]
Cybereasonmalicious.0b797d
PandaTrj/CI.A

How to remove NSIS:Adware-ADT [Trj]?

NSIS:Adware-ADT [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment